DocumentCode
3317674
Title
Markov model based experiment comparison
Author
Sharma, Swati ; Hussain, Alefiya
Author_Institution
CSE, IIT Delhi, Delhi, India
fYear
2012
fDate
3-7 Jan. 2012
Firstpage
1
Lastpage
2
Abstract
Network and cyber-security experiments are stochastic in nature, that is, experiment output is not deterministic due to dynamic network state. Comparing two correct experiment runs in these conditions is a domain that has not been completely explored yet. We propose a method to construct a first-order Markov model to capture and subsequently compare two runs of an experiment. Our model is based on transitions between different network events, and to create this first-order Markov model, we find all states from observed data and compute transition probabilities amongst them. Consequently, the model is saved in a repository. To compare two runs, we find the Euclidean Distance between this saved model and the observed model. We illustrate this concept on the DETER testbed by comparing different variations of the Kaminsky DNS cache poisoning attack experiment. Our observations show that comparison between similar experiments have negligible euclidean distances as compared to those between different experiment variations. Thus, we demonstrate that this methodology is promising and provides a principled approach for comparing two experiment runs.
Keywords
Markov processes; computer network security; probability; DETER testbed; Kaminsky DNS cache poisoning attack experiment; Markov model based experiment comparison; cyber-security experiments; dynamic network state; euclidean distances; first-order Markov model; transition probability; Analytical models; Computational modeling; Data models; Euclidean distance; Hidden Markov models; Markov processes; Mathematical model;
fLanguage
English
Publisher
ieee
Conference_Titel
Communication Systems and Networks (COMSNETS), 2012 Fourth International Conference on
Conference_Location
Bangalore
Print_ISBN
978-1-4673-0296-8
Electronic_ISBN
978-1-4673-0297-5
Type
conf
DOI
10.1109/COMSNETS.2012.6151363
Filename
6151363
Link To Document