Operational experiences with anomaly detection in backbone networks

  • Molina M
  • Paredes-Oliva I
  • Routly W
 et al. 
  • 26


    Mendeley users who have this article in their library.
  • 10


    Citations of this article.


Although network security is a crucial aspect for network operators, there are still very few works that have examined the anomalies present in large backbone networks and evaluated the performance of existing anomaly detection solutions in operational environments. The objective of this work is to fill this gap by reporting hands-on experience in the evaluation and deployment of an anomaly detection solution for the GÉANT backbone network. During this process, we analyzed three different commercial tools for anomaly detection and then deployed one of them for several months in the 18 points-of-presence of GÉANT. We first explain the general requirements that an anomaly detection system should satisfy from the point of view of a network operator. Afterwards, we describe the evaluation of the tools and present a study of the anomalies found in a continental backbone network after operationally using the finally deployed tool for half a year. We think that this first hand information can be of great interest to both professionals and researchers working on network security and can also guide future research towards more practical problems faced by network operators. © 2012 Elsevier Ltd. All rights reserved.

Author-supplied keywords

  • Anomaly detection
  • Benchmarking
  • NetFlow
  • Network management
  • Network security

Get free article suggestions today

Mendeley saves you time finding and organizing research

Sign up here
Already have an account ?Sign in

Find this document


  • Maurizio Molina

  • Ignasi Paredes-Oliva

  • Wayne Routly

  • Pere Barlet-Ros

Cite this document

Choose a citation style from the tabs below

Save time finding and organizing research with Mendeley

Sign up for free