2018
DOI: 10.1109/tifs.2017.2769018
|View full text |Cite
|
Sign up to set email alerts
|

An Effective Payload Attribution Scheme for Cybercriminal Detection Using Compressed Bitmap Index Tables and Traffic Downsampling

Abstract: 1  Abstract-Payload Attribution Systems (PAS) are one of the most important tools of network forensics for detecting an offender after the occurrence of a cybercrime. A PAS stores the network traffic history in order to detect the source and destination pair of a certain data stream in case a malicious activity occurs on the network. The huge volume of information that is daily transferred in the network means that the data stored by a PAS must be as compact and concise as possible. Moreover, the investigatio… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
10
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
2
1
1
1

Relationship

1
4

Authors

Journals

citations
Cited by 7 publications
(10 citation statements)
references
References 28 publications
0
10
0
Order By: Relevance
“…Unlike the previous studies [4]- [8], [11]- [13], [22], [23], [23]- [27], PayloadEmbeddings can extract contextual information from payloads. Each byte in a payload is transformed into a vector space by maximizing the log probability…”
Section: Other Techniquesmentioning
confidence: 97%
See 2 more Smart Citations
“…Unlike the previous studies [4]- [8], [11]- [13], [22], [23], [23]- [27], PayloadEmbeddings can extract contextual information from payloads. Each byte in a payload is transformed into a vector space by maximizing the log probability…”
Section: Other Techniquesmentioning
confidence: 97%
“…Applying the CPP technique, PCNAD uses 62.64% of the full payload length, on average. Hosseini et al [23] proposed a payload-based attribution scheme named CBID (Compressed Bitmap Index and Traffic Downsampling). CBID extracts features from down-sampled traffic using the combination of bloom filters and compressed bitmap index table.…”
Section: Other Techniquesmentioning
confidence: 99%
See 1 more Smart Citation
“…CBID is the most recent proposed PAS which is based on a combination of Bloom filter, Bitmap index table and a new traffic downsampling technique [13]. It outperforms the previous methods in terms of false positive rate.…”
Section: Related Workmentioning
confidence: 99%
“…Next studies have presented improved payload attribution systems in terms of false positive rate and data reduction ratio [10]- [13]. Nevertheless, an important problem that has not been adequately addressed by the previous works is wildcard queries.…”
Section: Introductionmentioning
confidence: 99%