Can the User Help? Leveraging User Actions for Network Profiling

Zorigtbaatar Chuluundorj, Curtis R. Taylor, Robert J. Walls, Craig A. Shue

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Enterprises have difficulty gaining insight into the steps preceding anomalous activity in end-user machines. En-Terprises may log events to later reconstruct anomalies to gain insight and determine their causes. Unfortunately, most logs are low-level and lack contextual information, making manual inspection arduous. Accordingly, enterprises may fail to promptly respond to anomalies, leading to outages or security breaches. To help these enterprises, we monitor and log each user's interactions with the machine's user interface (UI) and link them to the resulting network flows. We design, implement, and evaluate an SDN system, called Harbinger, for the Microsoft Windows OS that provides user activity context for flows. Enterprises can use the context we gather to complement traditional analysis. We explore how Harbinger can help differentiate normal and abnormal network traffic. While IP or DNS host name profiling can have error rates between 29%-38 % for URL-based traffic, UI-Aware sensors can reduce such errors to 0.2%. We further find that with the help of user action tracking, we can detect errant network traffic 99.1% of the time in our tests. HARBINGERhas good performance, introducing less than 6 milliseconds of delay in 95% of new network flows.

Original languageEnglish
Title of host publication2021 8th International Conference on Software Defined Systems, SDS 2021
EditorsPradeeban Kathiravelu, Jaime Lloret Mauri, Yaser Jararweh, Elhadj Benkhelifa, Sandra Sendra
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665458207
DOIs
StatePublished - 2021
Event8th International Conference on Software Defined Systems, SDS 2021 - Virtual, Gandia, Spain
Duration: Dec 6 2021Dec 9 2021

Publication series

Name2021 8th International Conference on Software Defined Systems, SDS 2021

Conference

Conference8th International Conference on Software Defined Systems, SDS 2021
Country/TerritorySpain
CityVirtual, Gandia
Period12/6/2112/9/21

Funding

ACKNOWLEDGMENTS This material is based upon work supported by the National Science Foundation under Grant No. 1422180. Shue holds stock in ContexSure Networks, Inc., an arrangement that has been reviewed and approved by WPI.

Fingerprint

Dive into the research topics of 'Can the User Help? Leveraging User Actions for Network Profiling'. Together they form a unique fingerprint.

Cite this