Download Multi-Protocol Correlation: Data Record Analyses and Correlator

Transcript
CHAPTER 2. BACKGROUND
2.2
Correlation
Correlation is an important concept to understand in this thesis. There are many
different types of correlation possible in this area of telecommunication. The easiest one to understand is message correlation, and after that comes xDR correlation.
xDR correlation is difficult because it can be on both protocols and services. Finally, the highest level of correlation is end-to-end correlation.
2.2.1
Concept of Correlation
The concept of correlation is rooted in statistical mathematics. The basic concept
is to use statistical probably to say whether there is a connection between two or
more units. If the probability is above a certain threshold then we can say that they
belong together can connect them together.
2.2.2
Data Topography
The topography of the gathered data can help in many cases of correlation, either
by speeding up the correlation process or by previously uncorrelatable cases. This
is due to the addition information that a correlator will know about the system.
Unfortunately, in many cases topography is not known. Proposed solution in this
thesis will assume that topography is not know, this is done for two reasons. The
first reason is because the solution is to be constructed in such a way that it will
be generic and user configurable, and that make it difficult to map this solution
to any one network topography. Additionally making it configurable for network
topography is such a large task that it is a master thesis in itself and not part of this
thesis.
24