Skip to main content
Article
Modeling Repeating Behaviors in Packet Arrivals: Detection and Measurement
Proceedings - IEEE INFOCOM
  • Jianfeng Li
  • Jing Tao
  • Xiaobo Ma
  • Junjie Zhang, Wright State University - Main Campus
  • Xiaohong Guan
Document Type
Conference Proceeding
Publication Date
8-21-2015
Disciplines
Abstract

With the growing stickiness of the Internet, numerous automated programs running in terminal facilities (e.g., laptops) tend to keep closely connected to the Internet by repetitively interacting with remote services. It is of fundamental importance to study such repeating behaviors of automated programs in areas like traffic engineering and network monitoring. This paper focuses on repeating behaviors in packet arrivals that are of interest, aiming at a hierarchical characterization of packet arrivals, detection methods and quantitative metrics. To this end, we present a structure-oriented characterization of packet arrivals, which reflects the temporal structure of repeating behaviors at different scales. Based on such characterization, a repeating behavior detection method is proposed by leveraging online-learning prediction, and two novel metrics of repeating behaviors are proposed from different aspects. In addition, a denoising method is developed to enhance the noise-tolerant capability of detection and measurement in face of noises. Experimental results based on real-world traces demonstrate the effectiveness of our proposed approaches in automated program behavior detection and behavioral botnet analysis.

DOI
10.1109/INFOCOM.2015.7218635
Citation Information
Jianfeng Li, Jing Tao, Xiaobo Ma, Junjie Zhang, et al.. "Modeling Repeating Behaviors in Packet Arrivals: Detection and Measurement" Proceedings - IEEE INFOCOM (2015) p. 2461 - 2469 ISSN: 0743166X
Available at: http://works.bepress.com/junjie_zhang/23/