• DocumentCode
    1121851
  • Title

    Estimation of message source and destination from network intercepts

  • Author

    Justice, Derek ; Hero, Alfred O., III

  • Author_Institution
    Dept. of Electr. Eng. & Comput. Sci., Michigan Univ., Ann Arbor, MI
  • Volume
    1
  • Issue
    3
  • fYear
    2006
  • Firstpage
    374
  • Lastpage
    385
  • Abstract
    We consider the problem of estimating the endpoints (source and destination) of a transmission in a network based on partial measurement of the transmission path. Possibly asynchronous sensors placed at various points within the network provide the basis for endpoint estimation by indicating that a specific transmission has been intercepted at their assigned locations. During a training phase, test transmissions are made between various pairs of endpoints in the network and the sensors they activate are noted. Sensor activations corresponding to transmissions with unknown endpoints are also observed in a monitoring phase. A semidefinite programming relaxation is used in conjunction with the measurements and linear prior information to produce likely sample topologies given the data. These samples are used to generate Monte Carlo approximations of the posterior distributions of source/destination pairs for measurements obtained in the monitoring phase. The posteriors allow for maximum a posteriori (MAP) estimation of the endpoints along with computation of some resolution measures. We illustrate the method using simulations of random topologies
  • Keywords
    Monte Carlo methods; data communication; maximum likelihood estimation; telecommunication network topology; Monte Carlo approximations; asynchronous sensors; endpoint maximum a posteriori estimation; likely sample topologies; linear prior information; message destination estimation; message source estimation; network intercepts; network transmission path; partial measurement; posterior distributions; random topologies; resolution measures; semidefinite programming relaxation; source-destination pairs; Computational modeling; Data acquisition; Data communication; Linear programming; Monitoring; Monte Carlo methods; Network topology; Phase measurement; Testing; Time measurement; Channel and network models; data acquisition and sensor models; detection and identification of anomalous events; network tomography and surveillance;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2006.879291
  • Filename
    1673398