BigBen: Telemetry Processing for Internet-wide Event Monitoring

11/22/2020
by   Meenakshi Syamkumar, et al.
0

This paper describes BigBen, a network telemetry processing system designed to enable accurate and timely reporting of Internet events (e.g., outages, attacks and configuration changes). BigBen is distinct from other Internet-wide event detection systems in its use of passive measurements of Network Time Protocol (NTP) traffic. We describe the architecture of BigBen, which includes (i) a distributed NTP traffic collection component, (ii) an Extract Transform Load (ETL) component, (iii) an event identification component, and (iv) a visualization and reporting component. We also describe a cloud-based implementation of BigBen developed to process large NTP data sets and provide daily event reporting. We demonstrate BigBen on a 15.5TB corpus of NTP data. We show that our implementation is efficient and could support hourly event reporting. We show that BigBen identifies a wide range of Internet events characterized by their location, scope and duration. We compare the events detected by BigBen vs. events detected by a large active probe-based detection system. We find only modest overlap and show how BigBen provides details on events that are not available from active measurements. Finally, we report on the perspective that BigBen provides on Internet events that were reported by third parties. In each case, BigBen confirms the event and provides details that were not available in prior reports, highlighting the utility of the passive, NTP-based approach.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/24/2018

The Online Event-Detection Problem

Given a stream S = (s_1, s_2, ..., s_N), a ϕ-heavy hitter is an item s_i...
research
09/28/2022

Internet Outage Detection using Passive Analysis (Poster Abstract and Poster)

Outages from natural disasters, political events, software or hardware i...
research
01/25/2009

Model-Based Event Detection in Wireless Sensor Networks

In this paper we present an application of techniques from statistical s...
research
03/29/2016

Detecting weak changes in dynamic events over networks

Large volume of networked streaming event data are becoming increasingly...
research
12/31/2021

Privacy-Protecting COVID-19 Exposure Notification Based on Cluster Events

We provide a rough sketch of a simple system design for exposure notific...
research
08/27/2018

SD-WAN Internet Census

The concept of software defined wide area network (SD-WAN or SDWAN) is c...
research
09/18/2019

Modeling the occurrence of events subject to a reporting delay via an EM algorithm

A delay between the occurrence and the reporting of events often has pra...

Please sign up or login with your details

Forgot password? Click here to reset