English
Related papers

Related papers: Catching Unusual Traffic Behavior using TF-IDF-bas…

200 papers

Early detection of significant traumatic events, e.g. a terrorist attack or a ship capsizing, is important to ensure that a prompt emergency response can occur. In the modern world telecommunication systems could play a key role in ensuring…

Computers and Society · Computer Science 2024-07-03 Qianru Zhou , Stephen McLaughlin , Alasdair J. G. Gray , Shangbin Wu , Chengxiang Wang

Time-to-Live data in the IP header offers two interesting characteristics: First, different IP stacks pick different start TTL values. Second, each traversed router should decrement the TTL value. The combination of both offers host and…

Networking and Internet Architecture · Computer Science 2016-06-27 Quirin Scheitle , Oliver Gasser , Paul Emmerich , Georg Carle

Anomaly detection is the practice of identifying items or events that do not conform to an expected behavior or do not correlate with other items in a dataset. It has previously been applied to areas such as intrusion detection, system…

Networking and Internet Architecture · Computer Science 2018-01-31 James Zhang , Ilija Vukotic , Robert Gardner

In this paper, we propose a new method for detecting unauthorized network intrusions, based on a traffic flow model and Cisco NetFlow protocol application. The method developed allows us not only to detect the most common types of network…

Cryptography and Security · Computer Science 2017-02-20 Aleksey A. Galtsev , Andrei M. Sukhov

Recent work in traffic analysis has shown that traffic patterns leaked through side channels can be used to recover important semantic information. For instance, attackers can find out which website, or which page on a website, a user is…

Cryptography and Security · Computer Science 2011-09-02 Xun Gong , Negar Kiyavash , Nabíl Schear , Nikita Borisov

In recent years, computer networks have become more and more advanced in terms of size, applications, complexity and level of heterogeneity. Moreover, availability and performance are important issues for end users. New types of…

Networking and Internet Architecture · Computer Science 2018-01-17 Mouhammd Alkasassbeh

Intrusion detection systems (IDS) are used to monitor networks or systems for attack activity or policy violations. Such a system should be able to successfully identify anomalous deviations from normal traffic behavior. Here we discuss the…

Cryptography and Security · Computer Science 2022-05-17 M. Andrecut

Traffic violations like illegal parking, illegal turning, and speeding have become one of the greatest challenges in urban transportation systems, bringing potential risks of traffic congestions, vehicle accidents, and parking difficulties.…

Computers and Society · Computer Science 2020-08-24 Zhihan Jiang , Longbiao Chen , Binbin Zhou , Jinchun Huang , Tianqi Xie , Xiaoliang Fan , Cheng Wang

In this paper, we aim to monitor the flow of people in large public infrastructures. We propose an unsupervised methodology to cluster people flow patterns into the most typical and meaningful configurations. By processing 3D images from a…

Computer Vision and Pattern Recognition · Computer Science 2019-02-12 João Carvalho , Manuel Marques , João P. Costeira

This paper pioneers a nonroutine network traffic prediction (NNTP) method to prospectively provide a theoretical basis for avoiding large-scale network disruption by accurately predicting bursty traffic. Certain events that impact user…

Networking and Internet Architecture · Computer Science 2024-10-22 Liangzhi Wang , Haoyuan Zhu , Jiliang Zhang , Zitian Zhang , Jie Zhang

In a variety of applications, one desires to detect groups of anomalous data samples, with a group potentially manifesting its atypicality (relative to a reference model) on a low-dimensional subset of the full measured set of features.…

Networking and Internet Architecture · Computer Science 2015-11-04 Zhicong Qiu , David J. Miller , George Kesidis

Application of deep learning to enhance the accuracy of intrusion detection in modern computer networks were studied in this paper. The identification of attacks in computer networks is divided in to two categories of intrusion detection…

Cryptography and Security · Computer Science 2020-12-16 Jafar Majidpour , Hiwa Hasanzadeh

Passive measurement has traditionally focused on inbound traffic to detect malicious activity, based on the assumption that threats originate externally. In this paper, we offer a complementary perspective by examining outbound traffic, and…

Networking and Internet Architecture · Computer Science 2026-01-13 Andrea Sordello , Zhihao Wang , Kai Huang , Alessandro Cornacchia , Marco Mellia

The worldwide growth of maritime traffic and the development of the Automatic Identification System (AIS) has led to advances in monitoring systems for preventing vessel accidents and detecting illegal activities. In this work, we describe…

Machine Learning · Computer Science 2019-08-15 Lucas May Petry , Amilcar Soares , Vania Bogorny , Stan Matwin

A covert attack method often used by APT organizations is the DNS tunnel, which is used to pass information by constructing C2 networks. And they often use the method of frequently changing domain names and server IP addresses to evade…

Networking and Internet Architecture · Computer Science 2022-07-15 Xin Ma , Shize Guo , Zhisong Pan , Bin Liu , Kaolin Jiang , Ming Chen , Shijiao Tang

Streaming anomaly detection refers to the problem of detecting anomalous data samples in streams of data. This problem poses challenges that classical and deep anomaly detection methods are not designed to cope with, such as conceptual…

Machine Learning · Computer Science 2022-10-12 Joseph Gallego-Mejia , Oscar Bustos-Brinez , Fabio Gonzalez

In this paper we propose a novel approach to identify anomalies in DNS traffic. The traffic time-points data is transformed to a string, which is used by new fast appproximate string matching algorithm to detect anomalies. Our approach is…

Cryptography and Security · Computer Science 2019-05-24 Roni Mateless , Michael Segal

Current probabilistic flow-size monitoring can only detect heavy hitters (e.g., flows utilizing 10 times their permitted bandwidth), but cannot detect smaller overuse (e.g., flows utilizing 50-100% more than their permitted bandwidth).…

Networking and Internet Architecture · Computer Science 2021-02-03 Simon Scherrer , Che-Yu Wu , Yu-Hsi Chiang , Benjamin Rothenberger , Daniele E. Asoni , Arish Sateesan , Jo Vliegen , Nele Mentens , Hsu-Chun Hsiao , Adrian Perrig

In the Internet age, cyber-attacks occur frequently with complex types. Traffic generated by access activities can record website status and user request information, which brings a great opportunity for network attack detection. Among…

Cryptography and Security · Computer Science 2018-11-01 Yuqi Yu , Hanbing Yan , Hongchao Guan , Hao Zhou

Events deviating from normal traffic patterns in driving, anomalies, such as aggressive driving or bumpy roads, may harm delivery efficiency for transportation and logistics (T&L) business. Thus, detecting anomalies in driving is critical…

Machine Learning · Computer Science 2022-12-16 Chung-Hao Lee , Yen-Fu Chen