Detecting Hidden User Behavior for Network Data Stream
Aiping Zhou, Lijun Liu, Huisheng Zhu, Jinhai Li, Chengang Zhu
Abstract
Aiping Zhou, Lijun Liu, Huisheng Zhu, Jinhai Li, Chengang Zhu
Abstract
Since hidden user behavior deliberately does not send packets during some time slots, it can easily evade such detection of traditional long-duration flow. To this end, we propose detection of hidden user behavior for network data stream (DUB). The main advantage of our approach is that it can use a flow persistence metric to detect hidden user behavior by a novel data structure. It only takes some simple computing and sets one bit for each sampled flow. Moreover, it can accurately estimate persistence of each flow. Hidden user behavior is detected using the estimated flow persistence by probabilistic counting approach efficiently. Our approach mainly consists of packet preprocessing, flow sampling, persistence estimating, persistent flow detecting. The experiments are conducted on the real network traffic and the testing results show that the proposed method outperforms the related ones in terms of estimation accuracy, detection accuracy and time overhead.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Since hidden user behavior deliberately does not send packets during some time slots, it can easily evade such detection of traditional long-duration flow. To this end, we propose detection of hidden user behavior for network data stream (DUB). The main advantage of our approach is that it can use a flow persistence metric to detect hidden user behavior by a novel data structure. It only takes some simple computing and sets one bit for each sampled flow. Moreover, it can accurately estimate persistence of each flow. Hidden user behavior is detected using the estimated flow persistence by probabilistic counting approach efficiently. Our approach mainly consists of packet preprocessing, flow sampling, persistence estimating, persistent flow detecting. The experiments are conducted on the real network traffic and the testing results show that the proposed method outperforms the related ones in terms of estimation accuracy, detection accuracy and time overhead.
Key concepts: Computer science, Network packet, Metric (unit), Preprocessor, Overhead (engineering), Probabilistic logic, Data pre-processing, Flow network