Title :
Modeling repeating behaviors in packet arrivals: Detection and measurement
Author :
Jianfeng Li ; Jing Tao ; Xiaobo Ma ; Junjie Zhang ; Xiaohong Guan
Author_Institution :
MOE KLINNS Lab., Xi´an Jiaotong Univ., Xi´an, China
fDate :
April 26 2015-May 1 2015
Abstract :
With the growing stickiness of the Internet, numerous automated programs running in terminal facilities (e.g., laptops) tend to keep closely connected to the Internet by repetitively interacting with remote services. It is of fundamental importance to study such repeating behaviors of automated programs in areas like traffic engineering and network monitoring. This paper focuses on repeating behaviors in packet arrivals that are of interest, aiming at a hierarchical characterization of packet arrivals, detection methods and quantitative metrics. To this end, we present a structure-oriented characterization of packet arrivals, which reflects the temporal structure of repeating behaviors at different scales. Based on such characterization, a repeating behavior detection method is proposed by leveraging online-learning prediction, and two novel metrics of repeating behaviors are proposed from different aspects. In addition, a denoising method is developed to enhance the noise-tolerant capability of detection and measurement in face of noises. Experimental results based on real-world traces demonstrate the effectiveness of our proposed approaches in automated program behavior detection and behavioral botnet analysis.
Keywords :
Internet; invasive software; automated programs; botnet analysis; denoising method; noise tolerant capability; packet arrival detection method; packet arrival repeating behaviors; quantitative metrics; repeating behavior detection method; structure oriented characterization; Computers; Conferences; Couplings; Electronic mail; Indexes; Internet; Measurement; repeating behavior; temporal structure; traffic modeling;
Conference_Titel :
Computer Communications (INFOCOM), 2015 IEEE Conference on
Conference_Location :
Kowloon
DOI :
10.1109/INFOCOM.2015.7218635