c-zhong / hdv2013

0 stars 0 forks source link

What makes the changes in the data fields of web server 01 #3

Open c-zhong opened 11 years ago

c-zhong commented 11 years ago

Web server 01 in sub-network 01,- changes in different fields:

image

Observation: observable changes in the fields of "disk percentage" "process number" "load percentage" "physical memory percentage" in the time interval "2013-4-01- 20:52:07" to "2013-4-01 17:18:27" Hypothesis: the web server 01 in subnetwork 01 has been attacked and it stopped working.

ShawnXiao2007 commented 11 years ago

How come the data can be negative?

c-zhong commented 11 years ago

standard value

junxzm commented 11 years ago

Good hypothesis. I have handled the data for all the 15 servers.

Today I will look into the number 1A, 1B, 1C, 1D web server in subnetwork 01.

If number 01 web server in subnetwork 01 indeed stopped working, the others should take it over.

ShawnXiao2007 commented 11 years ago

Can you make it clearer how you standardized data?

movingname commented 11 years ago

Yes. Could you please explain more on the meaning of this graph? For example, what is the meaning of Y-axis? What is the meaning of the straight lines in this graph? Thanks!

c-zhong commented 11 years ago

standarize: subtract mean and divide by standard deviation The following is the original image that has not been standarized: The meaning of Y is the exact number of the value the corresponding field. e.g. for [disk percentage] field y=80%

1

movingname commented 11 years ago

I see. Thanks. One more question: for one filed at a time you have a line to display the value. But why it is not a point?

c-zhong commented 11 years ago

It's not a line, just made of a lot of nodes.

here is an example for just one field [disk percentage]:

image

The red are nodes, but there are too many, so it like a line the blue are lines connecting two nodes.

I hope I can find a way to zoom out.

movingname commented 11 years ago

Thanks.

junxzm commented 11 years ago

Hi All,

Today I made a video about the five web servers status in sub-network 01.

But I somehow forget to combine my several tables in the database.

So the video was too long.

After some eyes-hurting watching, I pretend to think that the 01 web server did not stop working.

Main reason:

The other four web servers acted almost the same as the main web server in sub-network 1.

Also the patterns were pretty regular, namely state1-state2-state1 balabalabalabala...

I will modify my data processing program. And I hope I can share you a short video showing all the attributes about the five web servers in the sub-networking 01.

PS: If you anyone has question about the servers, I can make a dynamic video for you to observe.

movingname commented 11 years ago

Great! Looking forward to your video!

movingname commented 11 years ago

Hi Chen,

In your first post, you said that:

observable changes in the fields of "disk percentage" "process number" "load percentage" "physical memory percentage" in the time interval "2013-4-01- 20:52:07" to "2013-4-01 17:18:27"

But can you further elaborate that? For example, how these fields changed (increase, decrease or disappear)? And also why there is a huge white space in the middle of the graph?

Thanks!

c-zhong commented 11 years ago

There are some errors in the data. I just found the data are not seriously ordered by time.