Search papers, labs, and topics across Lattice.
This paper formalizes the role classification problem for hosts within enterprise networks and introduces two algorithms that group hosts based on connection patterns, adapting to changes over time. The algorithms were implemented in a commercial network monitoring product and tested on two enterprise networks. Results demonstrate that the algorithms can reduce the number of groups by two orders of magnitude compared to the number of hosts, effectively reflecting the logical structure of the networks.
Uncover hidden network structure and simplify management by automatically classifying hosts into meaningful roles based on their connection patterns.
Role classification involves grouping hosts into related roles. It exposes the logical structure of a network, simplifies network management tasks such as policy checking and network segmentation, and can be used to improve the accuracy of network monitoring and analysis algorithms such as intrusion detection. This paper defines the role classification problem and introduces two practical algorithms that group hosts based on observed connection patterns while dealing with changes in these patterns over time. The algorithms have been implemented in a commercial network monitoring and analysis product for enterprise networks. Results from grouping two enterprise networks show that the number of groups identified by our algorithms can be two orders of magnitude smaller than the number of hosts and that the way our algorithms group hosts highly reflects the logical structure of the networks.