• DocumentCode
    623590
  • Title

    Disambiguation of residential wired and wireless access in a forensic setting

  • Author

    Sookhyun Yang ; Kurose, Jim ; Levine, Brian Neil

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Massachusetts, Amherst, MA, USA
  • fYear
    2013
  • fDate
    14-19 April 2013
  • Firstpage
    360
  • Lastpage
    364
  • Abstract
    Thousands of cases each year of child exploitation on P2P file sharing networks lead from an IP address to a home. A first step upon execution of a search warrant is to determine if the home´s open Wi-Fi or the closed wired Ethernet was used for trafficking; in the latter case, a resident user is more likely to be the responsible party. We propose methods that use remotely measured traffic to disambiguate wired and wireless residential medium access. Our practical techniques work across the Internet by estimating the perflow distribution of inter-arrival times for different home access network types. We observe that the change of inter-arrival time distribution is subject to several residentialfactors, including differences between OS network stacks, and cable network mechanisms. We propose a model to explain the observed patterns of inter-arrival times, and we study the ability of supervised learning classifiers to differentiate between wired and wireless access based on these remote traffic measurements.
  • Keywords
    IP networks; Internet; computer network security; digital forensics; home networks; learning (artificial intelligence); pattern classification; peer-to-peer computing; radio access networks; telecommunication traffic; wireless LAN; IP address; Internet; OS network stack; P2P file sharing network; Wi-Fi; cable network mechanism; child exploitation; closed wired Ethernet; forensic setting; home access network; interarrival time distribution; remote traffic measurement; residential factor; search warrant; supervised learning classifier; trafficking; wired residential medium access; wireless residential medium access; Entropy; Forensics; Internet; Linux; Logic gates; Throughput; Wireless communication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM, 2013 Proceedings IEEE
  • Conference_Location
    Turin
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4673-5944-3
  • Type

    conf

  • DOI
    10.1109/INFCOM.2013.6566795
  • Filename
    6566795