Differential analysis of Operating System indicators for anomaly detection in dependable systems: An experimental study. (February 2016)
- Record Type:
- Journal Article
- Title:
- Differential analysis of Operating System indicators for anomaly detection in dependable systems: An experimental study. (February 2016)
- Main Title:
- Differential analysis of Operating System indicators for anomaly detection in dependable systems: An experimental study
- Authors:
- Bondavalli, Andrea
Ceccarelli, Andrea
Brancati, Francesco
Santoro, Diego
Vadursi, Michele - Abstract:
- Highlights: First example of anomaly detection in dependable systems by differential OS indicators analysis. A random walk model is proposed and experimentally validated for anomaly detection at OS level. First-order time differences can be modeled as Cauchy or Laplace distributions in most of the cases. Abstract: Dependable complex systems often operate under variable and non-stationary conditions, which requires efficient and extensive monitoring and error detection solutions. Among the many, the paper focuses on anomaly detection techniques, which monitor the evolution of some specific indicators through time to identify anomalies, i.e. deviations from the expected operational behavior. The timely identification of anomalies in dependable, fault tolerant systems allows to timely detect errors in the services and react appropriately. In this paper, we investigate the possibility to monitor the evolution of indicators through time using the random walk model on indicators belonging to Operating Systems, specifically in our study the Linux Red Hat EL5. The approach is based on the experimental evaluation of a large set of heterogeneous indicators, which are acquired under different operating conditions, both in terms of workload and faultload, on an air traffic management target system. The statistical analysis is based on a best-fitting approach aiming to minimize the integral distance between the empirical data distribution and some reference distributions. The outcomes ofHighlights: First example of anomaly detection in dependable systems by differential OS indicators analysis. A random walk model is proposed and experimentally validated for anomaly detection at OS level. First-order time differences can be modeled as Cauchy or Laplace distributions in most of the cases. Abstract: Dependable complex systems often operate under variable and non-stationary conditions, which requires efficient and extensive monitoring and error detection solutions. Among the many, the paper focuses on anomaly detection techniques, which monitor the evolution of some specific indicators through time to identify anomalies, i.e. deviations from the expected operational behavior. The timely identification of anomalies in dependable, fault tolerant systems allows to timely detect errors in the services and react appropriately. In this paper, we investigate the possibility to monitor the evolution of indicators through time using the random walk model on indicators belonging to Operating Systems, specifically in our study the Linux Red Hat EL5. The approach is based on the experimental evaluation of a large set of heterogeneous indicators, which are acquired under different operating conditions, both in terms of workload and faultload, on an air traffic management target system. The statistical analysis is based on a best-fitting approach aiming to minimize the integral distance between the empirical data distribution and some reference distributions. The outcomes of the analysis show that the idea of adopting a random walk model for the development of an anomaly detection monitor for critical systems that operates at Operating System level is promising. Moreover, standard distributions such as Laplace and Cauchy, rather than Normal, should be used for setting up the thresholds of the monitor. Further studies that involve a new application, a different Operating System and a new layer (an Application Server) will allow verifying the generalization of the approach to other fault tolerant systems, monitored layers and set of indicators. … (more)
- Is Part Of:
- Measurement. Volume 80(2016:Feb.)
- Journal:
- Measurement
- Issue:
- Volume 80(2016:Feb.)
- Issue Display:
- Volume 80 (2016)
- Year:
- 2016
- Volume:
- 80
- Issue Sort Value:
- 2016-0080-0000-0000
- Page Start:
- 229
- Page End:
- 240
- Publication Date:
- 2016-02
- Subjects:
- System monitoring -- Measurements on computer systems -- OS anomalies -- Anomaly detection -- Dependability measurement -- Fault detection
Weights and measures -- Periodicals
Measurement -- Periodicals
Measurement
Weights and measures
Periodicals
530.8 - Journal URLs:
- http://www.sciencedirect.com/science/journal/02632241 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.measurement.2015.11.010 ↗
- Languages:
- English
- ISSNs:
- 0263-2241
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 5413.544700
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 868.xml