Network Topology Change Detection Based on Statistical Process Control.

Yan Liu,Lian Liu,Yu Yan
DOI: https://doi.org/10.1145/3409501.3409532
2020-01-01
Abstract:Network topology is one of the most important parts in network security situation awareness tasks. Considering that the topology may change due to network intrusion, adjustment of routing policies, etc., the traditional static topology analysis methods cannot capture the dynamic change of network topology with time, which leads to the problem of weak early warning ability. To find out the small trend changes of the network topology over time, a network topology change detection method is proposed based on statistical process control: 1) to simplify the continuous dynamics of network topology, the observation network is regarded as a sampling sequence of the topological networks that dynamically change with time, a longitudinal topological network is constructed; 2) to quantify the differences of network structure from multiple perspectives, network structure parameters of each period are selected and measured; 3) to find out the trendy structural change in the longitudinal topological network, the cumulative sum method in industrial control is introduced to evaluate the change of topological parameters and further track to the starting time of change. Extensive experiments are performed on the simulation data, showing that compared with simple parameter statistics method, the method proposed can be sensitive to network changes and trace back to the beginning of the trend change.
What problem does this paper attempt to address?