This quantity of the Lecture Notes in laptop technological know-how sequence includes all papers permitted for presentation on the tenth IFIP/IEEE overseas Workshop on dispensed structures: Operations and administration (DSOM’99), which happened on the ETH Zürich in Switzerland and used to be hosted through the pc Engineering and Networking Laboratory, TIK. DSOM’99 is the 10th workshop in a chain of annual workshops, and Zürich is proud to host this tenth anniversary of the IEEE/IFIP workshop. DSOM’99 follows hugely profitable conferences, the newest of which happened in Delaware, U.S.A. (DSOM'98), Sydney, Australia (DSOM'97), and L’Aquila, Italy (DSOM'96). DSOM workshops try and collect researchers from the realm of community and repair administration in either and academia to debate contemporary developments and to foster additional development during this ?eld. unlike the bigger administration symposia IM (In- grated community administration) and NOMS (Network Operations and administration S- posium), DSOM workshops stick to a single-track software, on the way to stimulate interplay and lively participation. The speci?c concentration of DSOM’99 is “Active applied sciences for community and repair Management,” re?ecting the present advancements within the ?eld of energetic and application- ble networks, and approximately half the papers during this workshop fall inside this category.

This deployment of interrelated detectors in multiple points of a network is a key to effective performance monitoring and fault detection. The architecture of NSADS is implementation-independent. It relies on a small number of behavioral and communication conventions. It consists of a number of simple system components (Figure 1) which are interconnected by communications links and provide time-stamped values (according to a fixed schedule) for further processing. The current implementation is in C for maximal efficiency.

Motivated by these algorithmic and system drawbacks in previous work, we recently designed a set of IP network/service anomaly detection algorithms, implemented a real-time distributed anomaly detection platform, and vigorously tested them. This platform is called the IP network and service anomaly detector (IP NSAD). Specifically, IP NSAD is: · Capable of adaptive and automated detection of anomalies in IP networks and their services in real time. NSAD uses as inputs SNMP based standard network/service observables such as MIB2 and RMON1/2 variables [31], · Capable of objective driven and highly effective anomaly detection.

Monitoring Distributed Systems. ACM Transactions on Computer Systems, Vol. 5. (1987) 121{50 11. : Tools for distributed Application Management. IEEE Computer, Vol. 24. 8 (1991) 42{51 12. : The tempest: A practical framework for network programmability. IEEE Network Magazine. 6 (1998) 13. : An architecture for monitoring, visualization, and control and gigabit networks,. IEEE Network Magazine, Vol. 11, 10 (1997) 32{38 14. : On-line Monitoring: A Tutorial. IEEE Computer, Vol. 28. 6 (1995) 72{78 15.

