
With the wide spread of the Internet and the increasing of the Internet users, the fact of concentrated accesses to a specific server becomes a critical problem and it is important to process those accesses effectively. Multihomed network is attracted much attention to provide stable and efficient Internet services. In this paper, we focus on the multihoming method in the IPv6 environment. In the IPv6 environment, each host can obtain multiple IP addresses from different ISPs on one network interface, thus the multihoming is relatively easier than that in IPv4 environment. Also, for the multihoming in the IPv6 environment neither special operations are needed in the client side nor deep technical knowledges are required to the administrator. However, since many ISPs adopt ingress filtering for security concern, a multihomed site should select a proper site-exit router according to the source IP addresses of the packets. In most site existing methods, a kind of source IP address dependent routing function is introduced which have some problems in terms of high deployment cost. In this paper, we propose a new site-exit router selection method using the routing header in the IPv6 environment. This method introduces two middle-wares, one in server that attaches a routing header which indicates a specific site-exit router, and the other in site-exit router that removes it. We implemented a prototype system and confirmed it worked well with reasonable overhead.
Low-rate attacks can conceal their traffic because their packets are at very low rates, which make it easy to bury themselves into the normal traffic. Thus, although a number of volume-based detection techniques are able to identify anomalies that trigger significant changes in traffic volume, they are not applicable to detecting low-rate attacks. Because of this, the problem of low-rate attacks has been attracting many researchers in the community of network security. In this study, for the first time we propose a method based on the normal behavior mode of traffic to detect outbreaks of low-rate attacks. The experimental result indicates that our proposal is efficient.
Web-based malware attacks have become one of the most serious threats that need to be addressed urgently. Several approaches that have attracted attention as promising ways of detecting such malware include employing various blacklists. However, these conventional approaches often fail to detect new attacks owing to the versatility of malicious websites. Thus, it is difficult to maintain up-to-date blacklists with information regarding new malicious websites. To tackle this problem, we propose a new method for detecting malicious websites using the characteristics of IP addresses. Our approach leverages the empirical observation that IP addresses are more stable than other metrics such as URL and DNS. While the strings that form URLs or domain names are highly variable, IP addresses are less variable, i.e., IPv4 address space is mapped onto 4-bytes strings. We develop a lightweight and scalable detection scheme based on the machine learning technique. The aim of this study is not to provide a single solution that effectively detects web-based malware but to develop a technique that compensates the drawbacks of existing approaches. We validate the effectiveness of our approach by using real IP address data from existing blacklists and real traffic data on a campus network. The results demonstrate that our method can expand the coverage/accuracy of existing blacklists and also detect unknown malicious websites that are not covered by conventional approaches.
We present the results of a comparative study on the design of meta-heuristic algorithms for achieving parabolic fairness in wireless channel allocation. Wireless channel allocation (WCA) is a basic problem of fair distribution of indivisible goods, in this case the allocation of channels to users in a wireless schedule. Parabolic fairness represents a state that coincides with maxmin fairness in fair end-to-end user traffic rate allocation. This state can also be represented by maximization of a special case of the ordered weighted averaging operator. The related task then is to find an algorithm to approximate that maximum value for the WCA as close as possible. Here, several heuristic approaches are taken into account: a simple annealing heuristic, its integration into an Iterated Local Search (ILS) and also the integration of ILS as local search of a memetic algorithm. The comparison gives that best results can be achieved by the ILS, with up to 2-3 times improved performance compared to other algorithms and for practically relevant problem dimensions.
In this paper, we present the concept design, and implementation of a novel network measurement system for the future Internet. The new protocol offers end-point applications a mechanism for utilizing internal information to maximize transport. By a cross-layer approach, we can automatically to collect information along a path while upholding a disclosure policy for the information. The protocol has been implemented on commonly used operating systems and has been tested on both commercial and test-bed networks. A peer-to-peer file sharing application has been modified to support the protocol and experiments shows that download times were reduced and bandwidth was used more efficiently.
The IP Multimedia Subsystem (IMS) supports many kinds of multimedia services and is constantly evolving to meet the growth of mobile services and Internet applications. However, the security specifications of IMS networks do not provide any features to protect the system against Denial of Service (DoS) attacks, so a malicious attack can block the system by congesting a core service of IMS. To address the DoS attack problem, we propose an anomaly-based detection system using the Tanimoto distance to identify deviations in the traffic. We use a modified moving average approach to select a threshold. We also propose using a momentum oscillator to detect a slightly increasing attack. We evaluated the ability of our technique to detect attacks using a comprehensive synthetic data set containing various malicious traffic. Experimental results show that our technique accurately identified attacks and has the flexibility to deal with many types of attack patterns.
The Domain Name System (DNS) is a key naming system used in the Internet. Recently, the deployment of IPv6 and the DNS pre-fetch function in web browsers has significantly changed DNS usage. Furthermore, content delivery networks (CDNs) use complicated DNS configurations together with small TTL values to control their traffic. These three factors significantly increase DNS traffic. Thus, the importance of DNS traffic analysis has been increasing to properly maintain DNS operations. This paper presents an analysis of DNS full-resolver traffic at the University of Tsukuba in Japan. What we found are 1) The deployment of IPv6 has increased queries from clients as much as 41%, 2) The deployment of CDNs increases the use of small TTL values, the use of CNAME resource records and the use of out-of-bailiwick DNS server names. Since these increases are making the DNS cache hit rate low and the DNS response slow without recognition by Internet users, this paper seeks to warn application designers of potential system design risks in current Internet applications.
In the today's Internet, the transaction communication such as web has become the most popular application. However, the current TCP is not efficient for the transaction communication because of the increase of the latency caused by two control overheads at the beginning of the end-to-end communication: the 3-way handshake and the slow start phase in the congestion control. Therefore, to reduce the latency caused by these overheads, I propose a new tranport framework for the transaction communication. Since only end nodes cannot omit these overheads, this framework employs router aggressive supports including the notification of the proper size of sending rate and the connection state management. In this paper, I describe my ideas and related research plan.
In microblogging services such as Twitter, users can choose whose posts they want to read by "following" other user accounts. Twitter users often have large social networks, thus many of them are overwhelmed with managing their network connections and dealing with information overload. We want to address this problem by automatically dividing the social network of a Twitter user into personal cliques, and annotating each clique with keywords to identify the common ground of a clique. Our proposed clique annotation method extracts keywords from the tweet history of the clique members and individually weights the extracted keywords of each clique member according to the relevance of their tweets for the clique. The keyword weight is influenced by two factors. The first factor is calculated based on the number of connections of a user within the clique, and the second factor depends on whether the user mainly publishes personal information or information of general interest. In an experiment, on average 36.25% of the keywords extracted from our proposed method were relevant for the cliques, as opposed to 31.78% for the baseline method, which does not weight keywords but only calculates term frequency. When we annotated only cliques formed around common interests, such as "baseball", our proposed method even extracted 50.67% of relevant keywords, as opposed to 42% for the baseline method. These results clearly indicate that our approach can improve clique annotation in social networks.
The increasing use of location-based services leads these users to publish their locations unintentionally. Adversarial attackers can identify the user and find sensitive locations where the user often visits. Although l-diversity can be applied to location data and protect the user's privacy by preserving variations of locations, it does not consider the difference of the adversary's knowledge and does not properly address each sensitive location. The sensitive locations vary depending on the adversary's knowledge which reflects the relationship between the adversary and the user. In this paper, we introduce multi-dimensional l-diversity (MDlD), an enhancement of location l-diversity, to control the privacy risk from published locations by considering the specific knowledge that an adversary has on the user. We also propose an anonymization algorithm that adopts both generalization and suppression of locations to satisfy the MDlD. To reduce information loss and to preserve the number of locations for each user as much as possible, our algorithm applies generalization preferentially to suppression. We also show the practicality of our algorithm based on experimental results which used two real world datasets. The results show the fact that MDlD enables the publication of precise enough location information while still preserving user's privacy.
Virtualization technologies are widely used, and include Live Migration which moves running virtual machines between different physical hypervisors for dynamic load-balancing. In addition, Global Live Migration with IP mobility is also proposed. It enables migration among distributed sites and provides continuation even if the network of the virtual machines was changed. However, it supports only IP unicast communication, not IP multicast communication. In this paper, we propose a mobility support mechanism for IP multicast on virtual machines, and evaluate its basic performance using prototype system. As a result, the proposed method can provide migration function continuously receiving multicast stream stopped same as ordinary Live Migration.
Content-Aware networking is the paradigm of network design, in which users' requests refer to the content instead of servers' addresses for accessing data. Such network architecture assumes that it is the responsibility of the network itself to locate content and deliver it to the user in the most efficient way. In Content-Aware Network (CAN), data objects are replicated on multiple server machines, on behalf of content publishers, with the use of caching protocol. Client user access the content from the most appropriate server, at the rate allocated by the CAN, which affects the perceived utility. In this paper the problem of content placement and transmission rate allocation is considered. The problem is formulated as maximizing the total income of CAN operator, which receives payments proportional to the utility from subscribed users. However, CAN operator needs to pay for link utilization to the physical network operator and for server storage space to the hosting company. A two-level decomposition algorithm is presented which can be used as a decision support tool for the CAN operator.
The BGP routing system today faces a serious scaling problem caused by the linear growth of the global routing table. To overcome the routing table explosion, the IETF is in the process of standardizing a new routing protocol, called Locator/Identifier Separation Protocol (LISP). The protocol is expected to shrink the routing table size by orders of magnitude. However, its deployment relies on the performance of the Map cache function that maintains bindings of locators and identifiers. In this paper, we emulate the Map cache function and evaluate its performance when deployed in large ISPs using real packet level traffic traces. Our measurement results show that LISP has the potential to decrease the routing table size by several orders of magnitude. We also show that small percentage of cache entries carry large volume of traffic and that majority of the cache entries are poorly utilized.
The cloud computing paradigm is now widely used thanks to its scalable on-demand resource management techniques. Since one of the most important challenges of cloud computing services is to stably provide their consumers with computing resources, it is necessary to investigate the performance of cloud computing services in actual operations. To study the realistic performance of cloud computing services, we propose in this paper deploying and operating a distributed cloud computing system as a web-based, nationwide image delivery service for the annual baseball championship game in Japan. Measurement results show that the proposed system has worked stably, though it raised some performance issues related to the highly loaded VM.
SSH services are run on many hosts with various scopes other than just operation, so dictionary attack against the service is a common security threat. SANS has reported the emergence of distributed SSH dictionary attacks, which are very stealthy in comparison with a simple one. Since even one success of such an attack causes serious problems, administrators should implement countermeasures. SSH dictionary attacks have been detected in two basic ways that rely on either log files or network traffic. Both approaches, however, have limitations. The first approach imposes upon administrators heavy maintenance costs, which grow linearly with the number of hosts in networks. The second approach cannot distinguish between successful and unsuccessful attacks. Of more immediate concern, neither approach is effective against stealthy attacks because the login attempts of these attacks have little impact on log files or network traffic. An ideal method would be able to detect individual attacks and distinguish between an attack's success or failure, using information derived from only network traffic. In this paper, we describe such a method, which was developed by combining two novel elements. First, on the basis of our assumptions, we use two criteria: "existence of a connection protocol" and "difference in the inter-arrival time of an auth-packet". These criteria are not available, though, owing to the confidentiality and flexibility of the SSH protocol. Second, we resolve this problem by identifying transition points of a sub-protocol through flow features and machine learning algorithms. We evaluate the effectiveness of the proposed method through experiments on real traffic traces collected at the edge in our campus networks. The experimental results are encouraging for this research direction, though they are derived from reduced datasets of SSH dictionary attacks and under simplifying assumptions. The significant contribution is the demonstration that an ideal method for detecting SSH dictionary attacks seems feasible.
Vast amounts of access/service requests toward particular websites may occur in a short period of time, triggered by specific events, such as natural disasters and breaking news. These HTTP requests can occur unexpectedly and can disable the website when the quantity exceeds capacity. In order to address the problem, we propose a Distributed Hash Tables (DHT) based HTTP access control system using an access ticket issuing mechanism with a suspension time. The proposed system employs two types of nodes for access control: the access node and the emulator node. A number of access nodes and emulator nodes construct a peer-to-peer overlay network for increasing scalability and robustness. By controlling the access timing for user using access tickets with suspension time, the number of simultaneous connections in the end server can be adjusted to remain within the limits of its capacity, even when some access nodes and emulator nodes suddenly drop out.
This research is the study about Thai consumers' intention to buy toward Facebook commerce. The goal of this study is to determine the relations among beliefs in the number of selected Facebook's features, attitude toward Facebook commerce, perception on ease of use in Facebook fan page, and consumers' intention to buy on F-Commerce. Consequently, the survey questionnaires were evaluated by the university graduated respondents. Every respondent is the Facebook user and is friend with at least one researcher on Facebook. Additionally, before filling the survey, they were asked to read the same given scenario and to observe different series of mock-up pictures according to their random group. After that, the collected data will be processed by reliability analysis, factor analysis, and regression analysis respectively. The results show that belief in people who like a Facebook fan page, belief in people who like a photo of an item, and belief in friends who like a Facebook page have respectively significant impact on consumers' attitude. Furthermore, attitude and perceived ease of use also have a significant effect on consumers' purchasing intention on Facebook commerce. Moreover, from the additional compare means, we also founded that the different close relationships of Facebook friends provides the different belief in friends who like a Facebook fan page.
In telecommunication services, alongside QoS, QoE provision has become essential, thus performance and quality evaluation measurement results need to reflect reality as much as possible. Our goal is to enhance QoE evaluation schemes and enable improved QoE provision for video applications and services anytime and anywhere. In order to eliminate potential erroneous conclusions of QoE assessment techniques, our paper reveals a novel topic of distortions caused by preconceptions based on prior technical knowledge of QoE measurement test subjects. In our analysis we introduce the differences from genuine QoE measurement results in 3G ubiquitous mobile video service scenarios where test subjects were aware of the service parameters during measurements. We show how subjects' evaluations were affected and investigate the identified phenomenon in terms of Mean Opinion Score deviations and the overall QoE result distortion.
The proliferation of Wi-Fi infrastructures has facilitated numerous indoor localization techniques using Wi-Fi location fingerprints. They make it possible to identify a room or a place in urban environment, which is especially important in enabling many interesting location-based services. As there are too many rooms and places such as cafes and restaurants to be recognized in urban environment, the crowdsourcing approach has been proposed to collect Wi-Fi location fingerprints based on user participation. However, its actual deployment in a large-scale urban environment presents numerous design and implementation challenges due to urban characteristics such as a large crowd, dense region, and device diversity. This paper presents Elekspot system, whose design goal is to support system scalability, device heterogeneity, robustness against lack of contributions, and localization accuracy. Through several experiments and implementation of actual applications targeting urban places we confirmed that the architecture and methods of Elekspot can effectively meet the design goals.
It is almost impossible to prepare for the risks of a disaster which comes only once in 1000 years. However, the March 11, 2011, earthquake, tsunami and nuclear accident in Japan taught us some serious lessons. During the time of the large-scale disaster we were unable to accomplish tasks we were not prepared for. In this paper we propose a resilient service for survivor identification, a service which tries to accomplish its purpose to withstand unexpected serious situations. The most important characteristics of our proposals are as follows; (1) The system should have a variety of means to accomplish its purpose in various situations. (2) The governance style of our system is not top-down but bottom-up and the prime decision makers are the people at the scene of the disaster. (3) Every provided means of our system share common data formats. (4) All collected data is stored and integrated into the united database Internet cloud service. (5) All collected data can be searched seamlessly in the cloud service. We have built a system called eOrneOruyo2' as a reference implementation for our proposal.