The Experts below are selected from a list of 3741 Experts worldwide ranked by ideXlab platform

Prasant Mohapatra - One of the best experts on this subject based on the ideXlab platform.

  • efficient data capturing for Network Forensics in cognitive radio Networks
    IEEE ACM Transactions on Networking, 2014
    Co-Authors: Shaxun Chen, Kai Zeng, Prasant Mohapatra
    Abstract:

    Network Forensics is an emerging interdiscipline used to track down cyber crimes and detect Network anomalies for a multitude of applications. Efficient capture of data is the basis of Network Forensics. Compared to traditional Networks, data capture faces significant challenges in cognitive radio Networks. In traditional wireless Networks, usually one monitor is assigned to one channel for traffic capture. This approach will incur very high cost in cognitive radio Networks because it typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's behavior, cognitive radio devices change their operating channels dynamically, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio Networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. We also propose a protocol that schedules multiple monitors to perform channel scanning and packet capturing in an efficient manner. Monitors are reused in the time domain, and geographic coverage is taken into account. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%-300%.

  • efficient data capturing for Network Forensics in cognitive radio Networks
    International Conference on Network Protocols, 2011
    Co-Authors: Shaxun Chen, Kai Zeng, Prasant Mohapatra
    Abstract:

    Network Forensics is widely used in tracking down criminals and detecting Network anomalies, and data capture is the basis of Network Forensics. Compared to traditional Networks, data capture faces significant challenges in cognitive radio Networks. In traditional wireless Networks, one monitor is usually assigned to one channel to capture traffic, which incurs very high cost in a cognitive radio Network because the latter typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's activity, cognitive radio devices change their operating channels randomly, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio Networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. In addition, a protocol is proposed to schedule multiple monitors to perform channel scan and packet capturing in an efficient manner. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%–300%.

Shaxun Chen - One of the best experts on this subject based on the ideXlab platform.

  • efficient data capturing for Network Forensics in cognitive radio Networks
    IEEE ACM Transactions on Networking, 2014
    Co-Authors: Shaxun Chen, Kai Zeng, Prasant Mohapatra
    Abstract:

    Network Forensics is an emerging interdiscipline used to track down cyber crimes and detect Network anomalies for a multitude of applications. Efficient capture of data is the basis of Network Forensics. Compared to traditional Networks, data capture faces significant challenges in cognitive radio Networks. In traditional wireless Networks, usually one monitor is assigned to one channel for traffic capture. This approach will incur very high cost in cognitive radio Networks because it typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's behavior, cognitive radio devices change their operating channels dynamically, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio Networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. We also propose a protocol that schedules multiple monitors to perform channel scanning and packet capturing in an efficient manner. Monitors are reused in the time domain, and geographic coverage is taken into account. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%-300%.

  • efficient data capturing for Network Forensics in cognitive radio Networks
    International Conference on Network Protocols, 2011
    Co-Authors: Shaxun Chen, Kai Zeng, Prasant Mohapatra
    Abstract:

    Network Forensics is widely used in tracking down criminals and detecting Network anomalies, and data capture is the basis of Network Forensics. Compared to traditional Networks, data capture faces significant challenges in cognitive radio Networks. In traditional wireless Networks, one monitor is usually assigned to one channel to capture traffic, which incurs very high cost in a cognitive radio Network because the latter typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's activity, cognitive radio devices change their operating channels randomly, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio Networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. In addition, a protocol is proposed to schedule multiple monitors to perform channel scan and packet capturing in an efficient manner. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%–300%.

Suleman Khan - One of the best experts on this subject based on the ideXlab platform.

  • Network Forensics review taxonomy and open challenges
    Journal of Network and Computer Applications, 2016
    Co-Authors: Suleman Khan, Abdullah Gani, Ainuddin Wahid Abdul Wahab, Muhammad Shiraz, Iftikhar Ahmad
    Abstract:

    In recent years, a number of Network Forensics techniques have been proposed to investigate the increasing number of cybercrimes. Network Forensics techniques assist in tracking internal and external Network attacks by focusing on inherent Network vulnerabilities and communication mechanisms. However, investigation of cybercrime becomes more challenging when cyber criminals erase the traces in order to avoid detection. Therefore, Network Forensics techniques employ mechanisms to facilitate investigation by recording every single packet and event that is disseminated into the Network. As a result, it allows identification of the origin of the attack through reconstruction of the recorded data. In the current literature, Network Forensics techniques are studied on the basis of forensic tools, process models and framework implementations. However, a comprehensive study of cybercrime investigation using Network Forensics frameworks along with a critical review of present Network Forensics techniques is lacking. In other words, our study is motivated by the diversity of digital evidence and the difficulty of addressing numerous attacks in the Network using Network Forensics techniques. Therefore, this paper reviews the fundamental mechanism of Network Forensics techniques to determine how Network attacks are identified in the Network. Through an extensive review of related literature, a thematic taxonomy is proposed for the classification of current Network Forensics techniques based on its implementation as well as target data sets involved in the conducting of forensic investigations. The critical aspects and significant features of the current Network Forensics techniques are investigated using qualitative analysis technique. We derive significant parameters from the literature for discussing the similarities and differences in existing Network Forensics techniques. The parameters include framework nature, mechanism, target dataset, target instance, forensic processing, time of investigation, execution definition, and objective function. Finally, open research challenges are discussed in Network Forensics to assist researchers in selecting the appropriate domains for further research and obtain ideas for exploring optimal techniques for investigating cyber-crimes.

  • a comprehensive review on adaptability of Network Forensics frameworks for mobile cloud computing
    The Scientific World Journal, 2014
    Co-Authors: Suleman Khan, Abdullah Gani, Ainuddin Wahid Abdul Wahab, Muhammad Shiraz, Qi Han
    Abstract:

    Network Forensics enables investigation and identification of Network attacks through the retrieved digital content. The proliferation of smartphones and the cost-effective universal data access through cloud has made Mobile Cloud Computing (MCC) a congenital target for Network attacks. However, confines in carrying out Forensics in MCC is interrelated with the autonomous cloud hosting companies and their policies for restricted access to the digital content in the back-end cloud platforms. It implies that existing Network Forensic Frameworks (NFFs) have limited impact in the MCC paradigm. To this end, we qualitatively analyze the adaptability of existing NFFs when applied to the MCC. Explicitly, the fundamental mechanisms of NFFs are highlighted and then analyzed using the most relevant parameters. A classification is proposed to help understand the anatomy of existing NFFs. Subsequently, a comparison is given that explores the functional similarities and deviations among NFFs. The paper concludes by discussing research challenges for progressive Network Forensics in MCC.

Kai Zeng - One of the best experts on this subject based on the ideXlab platform.

  • Redundant Sniffer Deployment for Multi-Channel Wireless Network Forensics With Unreliable Conditions
    IEEE Transactions on Cognitive Communications and Networking, 2020
    Co-Authors: Jing Xu, Kai Zeng, Shimin Gong, Dusit Niyato
    Abstract:

    Network Forensics refers to monitoring and analysis of Network traffic for the purpose of information gathering, legal evidence, or intrusion detection. Wireless sniffers are usually deployed to collect PHY/MAC-layer information to trace abnormal wireless traffic. For multi-channel wireless Networks, it becomes problematic to allocate each sniffer an appropriate monitoring channel due to the limited number of sniffers. This leads to the sniffer-channel assignment (SCA) problem that has been mostly studied assuming error-free channel conditions or known behavior of wireless users. In this paper, we study the SCA problem with more general settings. In particular, we introduce redundant sniffer deployment to combat against the unreliable channel conditions. This can be formulated as a non-linear integer program with the aim of maximizing the number of captured data packets. We propose both centralized and distributed algorithms to determine an optimal strategy. For unknown user behaviors, we formulate the redundant SCA problem as a multi-armed bandit problem and develop an online learning policy to find a balance between the exploitation, i.e., accuracy, and exploration, i.e., coverage, in channel monitoring. Simulation results reveal that the redundant sniffer deployment, though sacrificing the exploration opportunities in the learning process, is robust against the uncertainty of user activities and provides the optimal performance in terms of sensing accuracy and monitoring coverage.

  • efficient data capturing for Network Forensics in cognitive radio Networks
    IEEE ACM Transactions on Networking, 2014
    Co-Authors: Shaxun Chen, Kai Zeng, Prasant Mohapatra
    Abstract:

    Network Forensics is an emerging interdiscipline used to track down cyber crimes and detect Network anomalies for a multitude of applications. Efficient capture of data is the basis of Network Forensics. Compared to traditional Networks, data capture faces significant challenges in cognitive radio Networks. In traditional wireless Networks, usually one monitor is assigned to one channel for traffic capture. This approach will incur very high cost in cognitive radio Networks because it typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's behavior, cognitive radio devices change their operating channels dynamically, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio Networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. We also propose a protocol that schedules multiple monitors to perform channel scanning and packet capturing in an efficient manner. Monitors are reused in the time domain, and geographic coverage is taken into account. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%-300%.

  • efficient data capturing for Network Forensics in cognitive radio Networks
    International Conference on Network Protocols, 2011
    Co-Authors: Shaxun Chen, Kai Zeng, Prasant Mohapatra
    Abstract:

    Network Forensics is widely used in tracking down criminals and detecting Network anomalies, and data capture is the basis of Network Forensics. Compared to traditional Networks, data capture faces significant challenges in cognitive radio Networks. In traditional wireless Networks, one monitor is usually assigned to one channel to capture traffic, which incurs very high cost in a cognitive radio Network because the latter typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's activity, cognitive radio devices change their operating channels randomly, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio Networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. In addition, a protocol is proposed to schedule multiple monitors to perform channel scan and packet capturing in an efficient manner. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%–300%.

Wei Yu - One of the best experts on this subject based on the ideXlab platform.

  • cyber crime scene investigations c si through cloud computing
    International Conference on Distributed Computing Systems Workshops, 2010
    Co-Authors: Xinwen Fu, Zhen Ling, Wei Yu
    Abstract:

    Cloud computing brings opportunities for Network Forensics tracing Internet criminals in the distributed environment. We may use the new “pay-as-you-go” model of the cloud computing to deploy the on-demand cyber surveillance sentinels and conduct distributed trace back in complicated cyber crime scene investigations. To trace criminals abusing anonymous communication Networks such as Tor, law enforcement can deploy high-bandwidth Amazon EC2 sentinels into the Tor Network. Some sentinels are configured as Tor entry guards and others work as Tor exits nodes. With the high bandwidth and appropriate number of such sentinels, we can achieve a required probability that a Tor circuit passes through an entry sentinel and an exit sentinel in order to capture the suspects. The proposed “pay-as-you-go” traceback model is cost-effective since the investigation may last for just hours with effective traceback techniques. Our experiments demonstrate the feasibility of this new traceback strategy through the cloud.