Traffic data collection system, traffic data collection method, and traffic data collection program
A network monitoring system includes a reception module, an extraction module, and a recovery module. The reception module receives time-series data having a bandwidth value of a monitored network. The extraction module extracts a feature amount of the time-series data from the time-series data having the bandwidth value by applying a seasonal adjustment method to the time-series data. Accordingly, the extraction module transmits the feature amount of the time-series data via a network for collecting traffic data of the monitored network. The recovery module receives the feature amount of the time-series data via the network for collecting traffic data of the monitored network. Accordingly, the recovery module recovers the time-series data having the bandwidth value from the feature amount of the time-series data.
1 . A traffic data collecting system comprising a processor configured to execute operations comprising:
receiving time-series data having a bandwidth value of a monitored network;
extracting a feature amount of the time-series data from the time-series data having the bandwidth value by applying a seasonal adjustment method to the time-series data, wherein the extracting further comprises:
decomposing, based on a parameter of scatterplot smoothing (Loess) (STL) decomposition adjusted to the time-series data, the time-series data into a trend term, a seasonality term, and a residual error term, by applying seasonal and trend decomposition using locally estimated STL decomposition to the time-series data having the bandwidth value, and
extracting the feature amount of the time-series data from the trend term, the seasonality term, and the residual error term;
adjusting the parameter of the STL decomposition based on a change in size of the time-series data when the parameter is changed by determining whether a change in size of the time-series data exceeds a threshold, adjusts the parameter that is strength of seasonality in a case where the change in size of the time-series data does not exceed the threshold, and adjusts the parameter that is the number of trend change points in a case where the change in size of the time-series data exceeds the threshold;
transmitting the feature amount of the time-series data via a network for collecting traffic data of the monitored network;
receiving the feature amount of the time-series data via the network for collecting traffic data of the monitored network; and
recovering the time-series data having the bandwidth value from the feature amount of the time-series data.
2 . The traffic data collecting system according to claim 1 , wherein the adjusting further comprises adjusting the parameter in a case where the change in size of the time-series data exceeds the threshold.
3 . The traffic data collecting system according to claim 1 , wherein
the extraction module extracts an event term indicating a variation due to an event from the time-series data having the bandwidth value, and
the transmission module transmits the event term as the feature amount of the time-series data.
4 . The traffic data collecting system according to claim 1 , wherein
the extraction module extracts the feature amount of the time-series data from the time-series data having the bandwidth value in a predetermined period, and
the recovery module recovers the time-series data having the bandwidth value in the predetermined period, based on the feature amount of the time-series data and the predetermined period.
5 . The traffic data collecting system according to claim 1 , the processor further configured to execute operations comprising:
generating restored trend data from slope/intercept data and trend change points.
6 . The traffic data collecting system according to claim 5 , wherein the decoding further comprises producing reconstructed seasonal data by applying an inverse Fourier transform to spectral data.
7 . The traffic data collecting system according to claim 1 , wherein the parameter represents the number of trend change points in a case where the change in size of the time-series data exceeds the threshold.
8 . The traffic data collecting system according to claim 1 , wherein the parameter represents a size of a low-pass filter in a case where the change in size of the time-series data exceeds the threshold.
9 . A method for collecting traffic data which is executed by a computer, the method comprising:
receiving time-series data having a bandwidth value of a monitored network;
extracting a feature amount of the time-series data from the time-series data having the bandwidth value by applying a seasonal adjustment method to the time-series data, wherein the extracting further comprises:
decomposing, based on a parameter of scatterplot smoothing (Loess) (STL) decomposition adjusted to the time-series data, the time-series data into a trend term, a seasonality term, and a residual error term, by applying seasonal and trend decomposition using locally estimated STL decomposition to the time-series data having the bandwidth value, and
extracting the feature amount of the time-series data from the trend term, the seasonality term, and the residual error term;
adjusting a parameter of the STL decomposition based on a change in size of the time-series data when the parameter is changed by determining whether a change in size of the time-series data exceeds a threshold, adjusts the parameter that is strength of seasonality in a case where the change in size of the time-series data does not exceed the threshold, and adjusts the parameter that is the number of trend change points in a case where the change in size of the time-series data exceeds the threshold;
transmitting the feature amount of the time-series data via a network for collecting traffic data of the monitored network;
receiving the feature amount of the time-series data via the network for collecting traffic data of the monitored network; and
recovering the time-series data having the bandwidth value from the feature amount of the time-series data.
10 . The method for collecting traffic data according to claim 9 , the method further comprises:
decomposing, into a trend term, a seasonality term, and a residual error term, the time-series data having the bandwidth value by applying seasonal and trend decomposition using locally estimated scatterplot smoothing (Loess) (STL) decomposition to the time-series data and extracts the feature amount of the time-series data from the trend term, the seasonality term, and the residual error term.
11 . The method for collecting traffic data according to claim 9 , wherein the adjusting further comprises adjusting the parameter in a case where the change in size of the time-series data exceeds the threshold.
12 . The method for collecting traffic data according to claim 9 , the method further comprises:
extracting an event term indicating a variation due to an event from the time-series data having the bandwidth value, and
transmitting the event term as the feature amount of the time-series data.
13 . The method for collecting traffic data according to claim 9 , the method further comprises:
extracting the feature amount of the time-series data from the time-series data having the bandwidth value in a predetermined period, and
recovering the time-series data having the bandwidth value in the predetermined period, based on the feature amount of the time-series data and the predetermined period.
14 . The method according to claim 9 , wherein the parameter represents the number of trend change points in a case where the change in size of the time-series data exceeds the threshold.
15 . The method according to claim 9 , wherein the parameter represents a size of a low-pass filter in a case where the change in size of the time-series data exceeds the threshold.
16 . A computer-readable non-transitory recording medium storing computer-executable program instructions that when executed by a processor cause a computer to execute operations comprising:
receiving time-series data having a bandwidth value of a monitored network;
extracting a feature amount of the time-series data from the time-series data having the bandwidth value by applying a seasonal adjustment method to the time-series data, wherein the extracting further comprises:
decomposing, based on a parameter of scatterplot smoothing (Loess) (STL) decomposition adjusted to the time-series data, the time-series data into a trend term, a seasonality term, and a residual error term, by applying seasonal and trend decomposition using locally estimated STL decomposition to the time-series data having the bandwidth value, and
extracting the feature amount of the time-series data from the trend term, the seasonality term, and the residual error term;
adjusting a parameter of the STL decomposition based on a change in size of the time-series data when the parameter is changed by determining whether a change in size of the time-series data exceeds a threshold, adjusts the parameter that is strength of seasonality in a case where the change in size of the time-series data does not exceed the threshold, and adjusts the parameter that is the number of trend change points in a case where the change in size of the time-series data exceeds the threshold;
transmitting the feature amount of the time-series data via a network for collecting traffic data of the monitored network;
receiving the feature amount of the time-series data via the network for collecting traffic data of the monitored network; and
recovering the time-series data having the bandwidth value from the feature amount of the time-series data.
17 . The computer-readable non-transitory recording medium according to claim 16 , wherein the adjusting further comprises adjusting the parameter in a case where the change in size of the time-series data exceeds the threshold.
18 . The computer-readable non-transitory recording medium according to claim 16 , wherein the collecting traffic data method further comprises:
extracting an event term indicating a variation due to an event from the time-series data having the bandwidth value, and
transmitting the event term as the feature amount of the time-series data.
19 . The computer-readable non-transitory recording medium according to claim 16 , wherein the collecting traffic data method further comprises:
extracting the feature amount of the time-series data from the time-series data having the bandwidth value in a predetermined period, and
recovering the time-series data having the bandwidth value in the predetermined period, based on the feature amount of the time-series data and the predetermined period.
20 . The computer-readable non-transitory recording medium according to claim 16 , wherein the parameter represents the number of trend change points in a case where the change in size of the time-series data exceeds the threshold.
21 . The computer-readable non-transitory recording medium according to claim 16 , wherein the parameter represents a size of a low-pass filter in a case where the change in size of the time-series data exceeds the threshold.
22 . The computer-readable non-transitory recording medium according to claim 16 , wherein the parameter represents the number of trend change points in a case where the change in size of the time-series data exceeds the threshold.
23 . The computer-readable non-transitory recording medium according to claim 16 , wherein the parameter represents a size of a low-pass filter in a case where the change in size of the time-series data exceeds the threshold.