Stanislav Miskovic

dblp:71/8355 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
0since 2021 · last 2016
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-authorSecurity and privacy · 2 · 1 first-authorSystems, architecture and hardware · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
4 papers
Network measurement and analytics · 61% Routing and switching · 31% Wireless networking · 9%
Network and information security
1 paper
Network security · 100%

Topics — the 9 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics
traffic classification
0.422015
Automatic generation of mobile app signatures from traffic observations · INFOCOM 2015
FLOWR: a self-learning system for classifying mobileapplication traffic · SIGMETRICS 2014
Network measurement and analytics
traffic analysis
0.212015
Automatic generation of mobile app signatures from traffic observations · INFOCOM 2015
Wireless networking › wireless mesh network
multihop wireless network
0.112010
Routing Primitives for Wireless Mesh Networks: Design, Analysis and Experiments · INFOCOM 2010
Routing and switching
path selection
0.112010
Routing Primitives for Wireless Mesh Networks: Design, Analysis and Experiments · INFOCOM 2010
Routing and switching › routing
routing primitives
0.112010
Routing Primitives for Wireless Mesh Networks: Design, Analysis and Experiments · INFOCOM 2010
Routing and switching › wireless routing
wireless mesh network routing
0.112010
Routing Primitives for Wireless Mesh Networks: Design, Analysis and Experiments · INFOCOM 2010
Routing and switching
traffic engineering
0.112015
Automatic generation of mobile app signatures from traffic observations · INFOCOM 2015
Network measurement and analytics › mobile network measurement
mobile traffic analysis
0.112014
FLOWR: a self-learning system for classifying mobileapplication traffic · SIGMETRICS 2014
Network measurement and analytics
throughput degradation
0.012010
Routing Primitives for Wireless Mesh Networks: Design, Analysis and Experiments · INFOCOM 2010

Methods — techniques the papers use, named apart from their topics

supervised learning · 0.2self-learning · 0.2machine learning · 0.2protocol analysis · 0.1measurement study · 0.1
YearPublicationVenuePosition
2016 MAGMA network behavior classifier for malware traffic
Enrico Bocchi, Luigi Grimaudo, Marco Mellia, Elena Baralis, Sabyasachi Saha, Stanislav Miskovic, Gaspar Modelo-Howard, Sung-Ju Lee 0001
Comput. Networks6
2015 Network Connectivity Graph for Malicious Traffic Dissection
abstract
Malware is a major threat to security and privacy of network users. A huge variety of malware typically spreads over the Internet, evolving every day, and challenging the research community and security practitioners to improve the effectiveness of countermeasures. In this paper, we present a system that automatically extracts patterns of network activity related to a specific malicious event, i.e., a seed. Our system is based on a methodology that correlates network events of hosts normally connected to the Internet over (i) time (i.e., analyzing different samples of traffic from the same host), (ii) space (i.e., correlating patterns across different hosts), and (iii) network layers (e.g., HTTP, DNS, etc.). The result is a Network Connectivity Graph that captures the overall "network behavior" of the seed. That is a focused and enriched representation of the malicious pattern infected hosts exhibit, purified from ordinary network activities and background traffic. We applied our approach on a large dataset collected in a real commercial ISP where the aggregated traffic produced by more than 20,000 households has been monitored. A commercial IDS has been used to complement network data with alerts related to malicious activities. We use such alerts to trigger our processing system. Results shows that the richness of the Network Connectivity Graph provides a much more detailed picture of malicious activities, considerably enhancing our understanding.
Enrico Bocchi, Luigi Grimaudo, Marco Mellia, Elena Baralis, Sabyasachi Saha, Stanislav Miskovic, Gaspar Modelo-Howard, Sung-Ju Lee 0001
ICCCN6
2015 Automatic generation of mobile app signatures from traffic observations
abstract
There are network management, traffic engineering, and security practices adopted in today's networking that rely on the knowledge about what applications' traffic is passing through the networks. These practices might fail with mobile apps whose identity remains hidden in generic HTTP traffic. The main reason is that unlike traditional applications, most mobile apps do not use specific protocols or IP ports with distinctive features. Many enterprises and service providers are in a great need of regaining control over their networks that increasingly carry mobile traffic. In this paper we propose FLOWR, a system that automatically identifies mobile apps by continually learning the apps' distinguishing features via traffic analysis. FLOWR focuses solely on key-value pairs in HTTP headers and intelligently identifies the pairs suitable for app signatures. Our system employs a custom supervised learning approach that leverages a very limited knowledge of app-signature seeds and autonomously grows its capacity for app identification. The approach is motivated by a simple but effective hypothesis that unknown app-identifying features should co-occur with the known signatures. Our experimental results show a significant growth in flow identification coverage provided by FLOWR. Specifically, we show that FLOWR can achieve identification of 86-95% of flows related to their generating apps.
Stanislav Miskovic, Z. Morley Mao, Mario Baldi, Antonio Nucci, Thomas Andrews 0001
INFOCOM3
2015 AppPrint: Automatic Fingerprinting of Mobile Applications in Network Traffic
Stanislav Miskovic, Gene Moo Lee, Mario Baldi
PAM1
2014 Nazca: Detecting Malware Distribution in Large-Scale Networks
Luca Invernizzi, Stanislav Miskovic, Ruben Torres, Christopher Krügel, Sabyasachi Saha, Giovanni Vigna, Sung-Ju Lee 0001, Marco Mellia
NDSS2
2014 FLOWR: a self-learning system for classifying mobileapplication traffic
abstract
No abstract available.
Thomas Andrews 0001, Stanislav Miskovic, Z. Morley Mao, Mario Baldi, Antonio Nucci
SIGMETRICS4
2010 Routing Primitives for Wireless Mesh Networks: Design, Analysis and Experiments
abstract
In this paper, we consider routing in multi-hop wireless mesh networks. We analyze three standardized and commonly deployed routing mechanisms that we term "node-pair discovery" primitives. We show that use of these primitives inherently yields inferior route selection, irrespective of the protocol that implements them. This behavior originates due to overhead reduction actions that systematically yield insufficient distribution of routing information, effectively hiding available paths from nodes. To address this problem, we propose a set of "deter and rescue" routing primitives that enable nodes to discover their hidden paths by exploiting already available historic routing information. We use extensive measurements on a large operational wireless mesh network to show that with node-pair discovery primitives, inferior route selections occur regularly and cause long-term throughput degradations for network users. In contrast, the deter and rescue primitives largely identify and prevent selection of inferior paths. Moreover, even when inferior paths are selected, the new primitives reduce their duration by several orders of magnitude, often to sub-second time scales.
Stanislav Miskovic, Edward W. Knightly
INFOCOM1