Open divyapathak24 opened 1 year ago
Steps to generate normal pcap:
Pcap(2018 dir A)Top-1 prefix (/16) with highest syn-acks | Total SYNs | Total ACKs following SYNS / Total TCP flows Delay monitor monitors | % of SYNs followed by ACks | Avg of the Avg delay collected from aggregator every 1 sec |
---|---|---|---|---|
130000 | 13770 | 13463 | 97.77% | 222 msec |
130100 | 13480 | 13274 | 98.47% | 226 msec |
130200 | 13539 | 13254 | 97.89% | 229 msec |
130300 | 13366 | 13241 | 99.06% | 227 msec |
Note: Here, variables are delay and # packets per sec
Component 2: Control Plane collecting features after regular intervals
Component 3: ML model
-Delay monitor:
-Loss monitor:
Isolation Forest
Training data: Normal instances (normal, congestion/packet loss, link failure)
Testing data: Normal + attack instances
Question: Issue with the function of features
RoutScout experiments: - Work done so far and to-do items:
-Delay monitor:
Component 1: Implementation of collection logic for RTT - Delay monitor itself keeps a track of RTT Component 2: Todo: Features collected for normal (no congestion/pkt loss), normal link failure and attack experiments Component 3:Todo: plots 2&3