This work studies the jitter buffer management algorithm for Voice over IP in WebRTC. In particular, it details the core concepts of WebRTC’s jitter buffer management. Furthermore, it investigates how jitter buffer management algorithm behaves under network conditions with packet bursts. It also proposes an approach, different from the default WebRTC algorithm, to avoid distortions that occur under such network conditions. Under packet bursts, when the packet buffer becomes full, the WebRTC jitter buffer algorithm may discard all the packets in the buffer to make room for incoming packets. The proposed approach offers a novel strategy to minimize the number of packets discarded in the presence of packet bursts. Therefore, voice quality as perceived by the user is improved. ITU-T Rec. P.863, which also confirms the improvement, is employed to objectively evaluate the listening quality.
The continuous advancement of DDoS attack technology and an increasing number of IoT devices connected on 5G networks escalate the level of difficulty for DDoS mitigation. A growing number of researchers have started to utilise Deep Learning algorithms to improve the performance of DDoS mitigation systems. Real DDoS attack data has no labels, and hence, we present an intelligent attack mitigation (IAM) system, which takes an ensemble approach by employing Recurrent Autonomous Autoencoders (RAA) as basic learners with a majority voting scheme. The RAA is a target-driven, distributionenabled, and imbalanced clustering algorithm, which is designed to work with the ISP's blackholing mechanism for DDoS flood attack mitigation. It can dynamically select features, decide a reference target (RT), and determine an optimal threshold to classify network traffic. A novel Comparison-Max Random Walk algorithm is used to determine the RT, which is used as an instrument to direct the model to classify the data so that the predicted positives are close or equal to the RT. We also propose Estimated Evaluation Metrics (EEM) to evaluate the performance of unsupervised models. The IAM system is tested with UDP flood, TCP flood, ICMP flood, multi-vector and a real UDP flood attack data. Additionally, to check the scalability of the IAM system, we tested it on every subdivided data set for distributed computing. The average Recall on all data sets was above 98%.
The continuing development of 5G technology increases the number of devices connected to the internet, this provides an increasing potential for cybercriminals to orchestrate detrimental Distributed Denial of Service (DDoS) attacks. The research community continues to develop new techniques to respond to the growing demand for DDoS mitigation. The internet service provider (ISP) provides internet access for users, so the attack traffic arrives at this location before reaching the victim. Deploying the mitigation system within the ISP domain offers an efficient solution. Therefore, we propose a dynamic network traffic managing (DNTM) system, which encompasses an Attack Detector, an IP Prioritiser, a Traffic Manager, and a Netflow Classifier, for the ISP. The IP prioritiser categorises IP addresses into normal and suspicious classes. The Traffic Manager makes use of the existing ISP mechanisms including ingress & egress filtering, rate limiting, blackholing and normal routing to take different mitigation actions. The Netflow Classifier is a hybrid ensemble model that utilises both unsupervised and supervised learning techniques. The classifier employs two self-organising maps (SOMs) to label data to train a supervised ensemble unit, which includes Random Forests, Decision Trees, and Gradient Boosted Trees (SRDG), to get the final classification. The Netflow Classifier achieved over 96% average on recall, precision and F1 score on UDP flood, ICMP flood and TCP flood attack data sets.
DDoS attacks remain one of the top cyber threats targeting the financial, health care, retail, gaming, and political sectors, which affects Internet service disruption, data or monetary loss. Security experts have predicted that the development of 5G technology will increase the frequency and the vector of DDoS attacks. Moreover, enhanced DDoS attack technology utilises artificial intelligence [1], which will escalate the level of difficulty to identify malicious traffic correctly to mitigate the attack effectively. The Internet service provider (ISP) is the connector between the users and the Internet. Deploying DDoS mitigation systems within the ISP domain can offer an efficient solution. Therefore, we propose a dynamic learning system (DLS) for the ISP. The DLS is an unsupervised ensemble model using the Complete Autoencoder (CA) as base learners to classify network traffic. The utmost difference between the CA and the regular Autoencoder is that the CA exploits the imbalanced characteristic of the attack data to generate a binary classification via a class switch. When the predicted number of normal IP addresses is over 50% of the total IP addresses, the CA swaps the class of the IP addresses. The CA is directed by a reference object (RO), which is either a reference limit or the mean of a reference error function (RL1¯), to furnish the automation to the DLS. The DLS was trained with a TCP-ICMP flood attack and tested with a UDP-TCP and a UDP-TCP-ICMP flood attack data set. The average Recall, Precision and F1 Score are all above 0.97. Additionally, the DLS outperformed the K-means and the Self-Organising Map models on a UDP flood attack data set.
The emergence of the Mirai malware facilitated a DDoS attack vector to surge to almost 1 Tbps in 2016, instigated by less than 150,000 infected IoT devices. With the infection of five new IoT devices per minute, the size of Mirai botnet was enlarged to 2.5 millions devices by the end of 2016. The continuous adaptation of the Mirai malware enables the modern variant to dynamically update its malware scripts on the fly to launch even more advanced and malevolent DDoS attacks, which dramatically escalates the level of difficulty with mitigating DDoS attacks. Many researchers endeavour to develop mitigation systems to keep up with the increasing security threats. Nonetheless, most presented models provide inefficient solutions either by utilising auxiliary servers at the host site, on the cloud or at dedicated data scrubbing centres. Since internet service providers (ISPs) connect the internet with users, the mitigation system should be deployed within the ISP domain to deliver a more efficient solution. Accordingly, we propose a stacked self-organising map, which is a feature dynamic deep learning approach that utilises netflow data collected by the ISP to combat the dynamic nature of novel DDoS attacks.
A new Mirai variant found recently was equipped with a dynamic update ability, which increases the level of difficulty for DDoS mitigation. Continuous development of 5G technology and an increasing number of Internet of Things (IoT) devices connected to the network pose serious threats to cyber security. Therefore, researchers have tried to develop better DDoS mitigation systems. However, the majority of the existing models provide centralized solutions either by deploying the system with additional servers at the host site, on the cloud, or at third party locations, which may cause latency. Since Internet service providers (ISP) are links between the internet and users, deploying the defense system within the ISP domain is the panacea for delivering an efficient solution. To cope with the dynamic nature of the new DDoS attacks, we utilized an unsupervised artificial neural network to develop a hierarchical two-layered self-organizing map equipped with a twofold feature selection for DDoS mitigation within the ISP domain.
Disruption precipitated by Distributed Denial of Service (DDoS) attacks has escalated drastically in recent years. This is due to the deployment of faster network access technologies, innovative network reliant applications and leading edge devices like smart phones, tablets and Internet of Things (IoT). Applications running on these devices are increasing the dependency of high speed network services. Nonetheless, the main objective of DDoS attacks are to deprive legitimate users of network services by exhausting a victim’s bandwidth or hardware resources. Most current approaches offer centralized detection and mitigation. However, few proposals focus on deploying DDoS defense and mitigation systems within the ISP’s domain, which has the potential to provide scalable and distributed solutions for these attacks. This paper presents a lightweight DDoS attack mitigation system utilising self-organizing map algorithm to classify near real time netflow data collected by the ISP.
OSPF (Open Shortest Path First) is a routing protocol that helps to improve the performance of networks by calculating the shortest path from a packet start point to each possible destination. This is achieved by assigning costs to each hop in the network, usually based on the speed of the interface between each router, although other metrics may also be used.This paper describes the development of an algorithm and control mechanism to automatically and dynamically modify OSPF interface costs on Mikrotik routers based upon the amount of traffic flowing through a path, rather than the absolute shortest path.
We describe a novel approach to comparative assembly that directly integrates anchoring alignments into the contig assembly process, enabling the extension of contig construction through the boundaries of repeat nodes in a compressed de Bruijn graph. Our method exploits anchoring alignments, paired-read constraints and read threading as path selection heuristics while an assembly graph is transversed during contig construction. Tests and benchmarks against preeminent implementations of both comparative and de novo assembly models demonstrate that the approach can significantly increase the contiguity of an assembly without inducing a large number of misjoins and structural errors.
We present a fuzzy technique for approximate k-mer matching that combines the speed of hashing with the sensitivity of dynamic programming. Our approach exploits the collision detection mechanism used by hash maps, unifying the two phases of “seed and extend” into a single operation that executes in close to O(1) average time.
Although second generation sequencing technology can be used to rapidly sequence an entire genome, assembly algorithms require a high level of coverage to produce a complete genomic sequence. We describe a fuzzy k-mer approach that is capable of rapidly ordering and orientating low coverage sequence reads with a high level of accuracy. Using this approach, a draft genome of Mycoplasma genitalium, sampled at varying low levels of coverage, was accurately anchored against the genome of Mycoplasma pneumoniae. The anchored reads were assembled into scaffolds with a vastly increased N50 length and an error rate of <1.5%.
Although hash-based approaches to sequence alignment and genome assembly are long established, their utility is predicated on the rapid identification of exact k-mers from a hash-map or similar data structure. We describe how a fuzzy hash-map can be applied to quickly and accurately align a prokaryotic genome to the reference genome of a related species. Using this technique, a draft genome of Mycoplasma genitalium, sampled at 1X coverage, was accurately anchored against the genome of Mycoplasma pneumoniae. The fuzzy approach to alignment, ordered and orientated more than 65% of the reads from the draft genome in under 10 seconds, with an error rate of <1.5%. Without sacrificing execution speed, fuzzy hash-maps also provide a mechanism for error tolerance and variability in k-mer centric sequence alignment and assembly applications.
Modern medical devices have the facility to output data such as device settings and readings. Such devices include vital signs monitors, ventilators and infusion pumps to name a few. Wirelessly networking these types of devices has the advantages of patient mobility, device mobility and central data storage. This has led us to develop wireless sensors, gateways, servers and clients to support legacy medical devices. In this paper we present results from a hospital usability trial of this newly developed technology. We present the final wireless sensor network architecture used in the trial which also supports other compatible sensors we have developed. This also includes the architecture detail that supports the addition of future medical devices.
Wirelessly enabling medical devices such as vital signs monitors, ventilators and infusion pumps allows central data collection. This paper discusses how data from these types of devices can be integrated into hospital systems using wireless sensor networking technology. By integrating devices you are protecting investment and opening up the possibility of networking with similar devices. In this context we present how Zigbee meets our requirements for bandwidth, power, security and mobility. We have examined the data throughputs for various medical devices, the requirement of data frequency, security of patient data and the logistics of moving patients while connected to devices. The paper describes a new tested architecture that allows this data to be seamlessly integrated into a user interface or healthcare information system (HIS). The design supports the dynamic addition of new medical devices to the system that were previously unsupported by the system. To achieve this, the hardware design is kept generic and the software interface for different types of medical devices is well defined. These devices can also share the wireless resources with other types of sensors being developed in conjunction on this project such as wireless ECG (electrocardiogram) and pulse-oximetry sensors.
This paper describes the design, development and clinical trials completed on an ambulatory, wireless ECG / vital signs monitor, which was designed to work on standard wireless LAN networking systems (802.11b). It discusses the trials, results collected from two prototype sensor devices, the limitations of the system in place due to architecture and site location. Future works identified from the clinical trials completed will also be discussed.
This paper outlines a system for detection of cardiac arrhythmias within ECG signals, based on a Bayesian artificial neural network (ANN) classifier. The Bayesian (or probabilistic) ANN classifier is built by the use of a logistic regression model and the backpropagation algorithm based on a Bayesian framework. Its performance for this task is evaluated by comparison with other classifiers including Naive Bayes, decision trees, logistic regression, and RBF networks. A paired t-test is employed in comparing classifiers to select the optimum model. The system is evaluated using noisy ECG data, to simulate a real-world environment. It is hoped that the system can be further developed and fine-tuned for practical application.
A prerequisite of participating in an enterprise system is the ability to cope with the rigorous demands experienced within the system. In order to cope with these demands, a number of infrastructure support services are available to assist developers in their creation. A key obstacle to the widespread deployment of agent technology is the relative immaturity of agent technology with regard to its infrastructure. This paper presents a solution to the problem by offering enterprise-level infrastructure services to agent platforms in an agent friendly manner. The proposed solution uses ServiceAgent Gateways (SAG) to offer these services within an agent environment. This paper describes the SAG design pattern and presents an implementation of the pattern that offers the functionality of Enterprise Message Services (EMS) to an agent environment. The Java Message Service (JMS)-Agent Gateway enhances the acceptability of agent platforms within business environments, moving them a step closer to full-scale participation in the digital enterprise.
Identifying the optimum load balancing algorithm for a web site is a difficult and complex task. This paper examines a number of simulated algorithms based on a master/slave architecture. Three algorithms are used in order to have comparable results to discuss. The first algorithm is the use of a master/slave architecture and processing requests to the relevant servers as a batch of requests. The second algorithm investigated is the standard round robin algorithm used in a master/slave architecture. The final algorithm proposed in the paper is the use of a master/slave architecture that uses the round robin algorithm combined with a reverse proxy of requests. The use of this final combination of algorithms has showed a performance improvement of 19