DocumentCode
1121851
Title
Estimation of message source and destination from network intercepts
Author
Justice, Derek ; Hero, Alfred O., III
Author_Institution
Dept. of Electr. Eng. & Comput. Sci., Michigan Univ., Ann Arbor, MI
Volume
1
Issue
3
fYear
2006
Firstpage
374
Lastpage
385
Abstract
We consider the problem of estimating the endpoints (source and destination) of a transmission in a network based on partial measurement of the transmission path. Possibly asynchronous sensors placed at various points within the network provide the basis for endpoint estimation by indicating that a specific transmission has been intercepted at their assigned locations. During a training phase, test transmissions are made between various pairs of endpoints in the network and the sensors they activate are noted. Sensor activations corresponding to transmissions with unknown endpoints are also observed in a monitoring phase. A semidefinite programming relaxation is used in conjunction with the measurements and linear prior information to produce likely sample topologies given the data. These samples are used to generate Monte Carlo approximations of the posterior distributions of source/destination pairs for measurements obtained in the monitoring phase. The posteriors allow for maximum a posteriori (MAP) estimation of the endpoints along with computation of some resolution measures. We illustrate the method using simulations of random topologies
Keywords
Monte Carlo methods; data communication; maximum likelihood estimation; telecommunication network topology; Monte Carlo approximations; asynchronous sensors; endpoint maximum a posteriori estimation; likely sample topologies; linear prior information; message destination estimation; message source estimation; network intercepts; network transmission path; partial measurement; posterior distributions; random topologies; resolution measures; semidefinite programming relaxation; source-destination pairs; Computational modeling; Data acquisition; Data communication; Linear programming; Monitoring; Monte Carlo methods; Network topology; Phase measurement; Testing; Time measurement; Channel and network models; data acquisition and sensor models; detection and identification of anomalous events; network tomography and surveillance;
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2006.879291
Filename
1673398
Link To Document