MPI-INF Logo
Campus Event Calendar

Event Entry

What and Who

“Towards Uncovering Hidden Internet Traffic Characteristics" - PhD Defense by Aniss Maghsoudlou

Aniss Maghsoudlou
Max-Planck-Institut für Informatik - INET
Promotionskolloquium
AG 1, AG 2, AG 3, INET, AG 4, AG 5, D6, SWS, RG1, MMCI  
Public Audience
English

Date, Time and Location

Thursday, 14 December 2023
14:00
90 Minutes
E1 5
002
Saarbrücken

Abstract

With the growing digitization of human life, the Internet has become an inevitable utility. Since the Internet is designed in a non-centralized manner with a best-effort mindset, it is essential to measure different aspects of the Internet including security, performance, and scalability. The rise of remote work has emphasized the need for measuring security of the Internet traffic.


In this thesis, we first address the need for measuring large-scale Internet traffic to gain useful insights into the security and traffic trends in large Internet Service Providers (ISPs) and Internet eXchange Points (IXPs) by designing a system called Flowyager for querying network-wide flow data in a near real-time manner. Next, we propose FlowDNS to augment flow data with domain names to infer the actual service/domain to which the traffic belongs. This system lays the foundation for monito-ring the services that are being used and gives network operators the chance to predict their bandwidth demands. To gain a more comprehensive picture, we need to combine the results from the above-mentioned systems with active measurement techniques. This gives us the chance to dis-cover the existence and origin of hidden characteristics of the Internet traffic. For in-stance, in a large European ISP, we detect a large amount of Internet traffic using port number 0 when querying Flowyager. Complementing passive measurement results with active measurement techniques, we find that this traffic is mostly caused by fragmentati-on, scanning, and misconfigured devices. Finally, given the widespread usage of Virtual Private Networks (VPNs) during the COVID-19 pandemic for remote work, we strive to characterize VPN traffic in the Internet. We use active measurement techniques to detect VPN servers and analyze their security aspects. Then, with the help of FlowDNS, we detect VPN traffic on the Internet to provide insights about the VPN traffic patterns in the Internet.

This dissertation helps researchers and network operators to gain insights about some hidden characteristics of Internet traffic, and also provides the means to look for specific traffic patterns in the network flow data and investigate its characteristics.

Contact

Iris Wagner
+49 681 9325 3500
--email hidden
passcode not visible
logged in users only

Iris Wagner, 12/06/2023 15:14 -- Created document.