Angelos K. Marnerides

dblp:71/5300 · DBLP profile ↗
← Back
40ranked-venue papers
10as first author
15since 2021 · last 2026
0000-0002-7996-6216ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 29 · 10 first-author · 11 since 2021Security and privacy · 6 · 3 since 2021Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Accelerated Packet Forwarding for Quantum-Secured Communications
Lazaros Lazarou, Charalampos Theodorou, Angelos K. Marnerides
INFOCOM3
2026 BotPro: Data-driven tracking & profiling of IoT botnets in the wild
abstract
The incorporation of the IoT into modern sociotechnical systems, alongside the rapid manufacturing of IoT devices with minimal embedded security, has significantly altered the cyber threat landscape. Consequently, modern cyberattacks now exploit compromised IoT devices to launch large-scale volumetric assaults or sophisticated advanced persistent threats (APTs) via carefully coordinated IoT botnets. Given the ever-changing structural dynamics of these botnets, tracking their activities presents significant challenges since malicious actors frequently adapt and employ new evasion techniques to expand their networks. This study introduces BotPro, a novel open-source tool built on a data-driven framework that captures and attributes the behavioural characteristics of IoT botnets. BotPro integrates honeypot telemetry, CTI feeds, and Internet topology data to profile scanning, infection, and propagation patterns, as well as cluster payloads to identify malware variants and assess AS-level risk exposure. Through a macroscopic measurement study spanning three years with 40 globally distributed honeypots covering 193 countries and 16K ASes, we show that BotPro can quantify the tolerance of Autonomous Systems (ASes) as a function of botnet scanning and propagation properties. Our clustering evaluation achieved a Silhouette score of 0.54 with low Davies–Bouldin index values, confirming the coherence and separation of identified botnet groups. Hence, our findings provide substantial context to security experts and network operators for effectively designing and implementing next-generation defence and mitigation measures against current and future IoT botnets.
Hatem A. Almazarqi, Mathew Woodyard, Angelos K. Marnerides
Comput. Secur.3
2025 PQClass: Classification of Post-Quantum Encryption Applications in Internet Traffic
abstract
Post-quantum cryptography (PQC) is expected to revolutionize secure communications in next-generation digital ecosystems. Previous and ongoing activities demonstrate that different PQC algorithms significantly impact traffic latency, but they do not yet provide a scheme to assess the existence of the PQC algorithm or its identification when encrypted traffic is analyzed for traffic engineering purposes. Hence, this work is the first to propose a novel PQClass pipeline for classifying encrypted Internet traffic of recently NIST-approved PQC algorithms. Hence, it establishes solid grounds for enabling engineers to optimize their networks and, in parallel, for cybersecurity practitioners to familiarise themselves with PQC algorithmic properties for enhancing or devising security architectures in diverse setups. Our pipeline demonstrates impressive performance on real-world data, achieving 86% accuracy in detecting the presence of a PQC algorithm and 91% and 98% accuracy in identifying the browser and OS, respectively, based on PQC-based traffic.
Angelos K. Marnerides, Chen Hajaj, Revital Marbel, Ran Dubin, Amit Dvir
ICC1
2025 Dynamics of Large-Scale DDoS Attacks Orchestrated by IoT Botnets
abstract
The increasing prevalence of Internet of Things (IoT) devices has created new vulnerabilities that malicious actors can exploit, particularly for orchestrating large-scale Distributed Denial of Service (DDoS) attacks via IoT botnets. These botnets take advantage of the inherent weaknesses in IoT devices to overwhelm network infrastructure, resulting in significant disruptions. In this work, we offer an Internet measurements study focusing on the AS-level distribution of DDoS traffic produced by IoT botnets and their attribution based on propagation patterns. Hence, with the use of graph-based metrics we correlate Cyber Threat Intelligence (CTI) data from globally distributed honeypots with real DDoS attacks to profile botnet propagation patterns and further identify key Internet Autonomous Systems (ASes) being tolerant to these attacks via an exemplar use case. Our results highlight device-level vulnerabilities acting as main vessels for IoT botnet propagation resulting to maximise their impact in terms of DDoS attack scale. In general, we argue that the herein reported work provides valuable insights from the real global Internet towards developing next-generation early identification and post-attack mitigation strategies of DDoS attacks instrumented by IoT botnets.
Hatem A. Almazarqi, Mathew Woodyard, Angelos K. Marnerides
ISCC3
2025 Stratification and Profiling of IoT Botnet Variants
abstract
IoT botnets have been adopted as the prime infrastructure for a plethora of cybercrime and modern cyberwarfare. Evidently, conventional defence approaches fail to capture the full spectrum of IoT botnet activity by virtue of attackers evading schemes and limited Internet visibility. In this work, we develop a novel macroscopic analysis framework that profiles malware strains through payload signatures gathered from malicious traffic, revealing distinct botnet variants and their infrastructure. Through payload clustering distilled by information retrieval properties and DNS-based infrastructure mapping, we systematically group botnet families, identifying distinct exploitation trends and infrastructure reuse patterns. Our longitudinal study over real pre-captured datasets for a $\mathbf{4}$-year period reveals widespread lack of blacklist coverage with $65.94 \%$ of discovered malicious IPs and $\mathbf{9 8. 9 7 \%}$ of associated domains not yet blacklisted. We pinpoint a growing trend of botnet operators leveraging cloud services such as AWS, OVH, and Linode, hosting their command-and-control (C2) servers on reputable domains to bypass security filters and extend operational longevity. Through demonstrating practical metrics to assess botnet scan volume, vulnerability trends, and infection rates, we stress the need to refine existing defence mechanisms. In parallel, we set solid ground for practical threat hunting and risk profiling for next-generation cybersecurity schemes.
Michael Photiades, Mathew Woodyard, Hatem A. Almazarqi, Angelos K. Marnerides
ISCC4
2025 Advanced Persistent Threats Based on Supply Chain Vulnerabilities: Challenges, Solutions, and Future Directions
abstract
Due to the ever increasing interdependency across a variety of diverse software and hardware components in information and communications technology (ICT) provisioning, supply chain vulnerabilities (SCVs) targeting such dependencies have evolved as a primary choice for malicious actors to stealthy and complex cyber-attacks. The current modus operandi in the cyber threat spectrum is solely correlated with advanced persistent threats (APTs) that have shown to be prevalent across diversified attacks underpinning cyberwarfare and cybercrime. Hence, defense against such threats is undoubtedly considered as a high priority on a global scale. Nonetheless, the reliance on third-party supply chain software and device across diverse ICT ecosystems, combined with the current defense mechanisms’ inability to identify specific compromised entry points, results in an increased risk of APTs. This survey explores the state-of-the-art to stratify and showcase the properties of supply chain-based APTs, elaborate on reported risks from such APTs, and expand on existing defense methods. This study connects academic research with industry practices to highlight a new and growing problem. It examines supply chain compromises, offers unique insight into how these exploitations occur, and equips cybersecurity practitioners with the knowledge required to design next-generation APT defense mechanisms.
Zhuoran Tan, Shameem A. Puthiya Parambath, Christos Anagnostopoulos 0001, Jeremy Singer, Angelos K. Marnerides
IEEE Internet Things J.5
2024 Macroscopic Insights of IoT Botnet Dynamics Via AS-level Tolerance Assessment
abstract
The ubiquitous integration of the IoT in current sociotechnical systems alongside the manufacturing of IoT devices and IoT-enabled services equipped with minimal security, has profoundly altered the cyber-threat landscape. Consequently, the overwhelming majority of cyberattacks utilise compromised IoT devices as a vessel for initiating large scale volumetric (e.g., DDoS) or stealthy Advanced Persistent Threats (APTs) such as ransomware through well orchestrated IoT botnets. Due to the constantly evolving nature of these botnets and their diverse structural characteristics, tracking their activities poses considerable challenges since malicious actors and botnet owners often adopt new strategies to evade detection and expand their botnet network. Evidently, Autonomous Systems (ASes) and their implied organisational and regulatory properties play a crucial role in botnet propagation. In this paper, we present a novel and extensive macroscopic measurement study quantifying AS-level tolerance in the context of IoT botnet behavioral dynamics across the global IPv4 address space. In order to verify and justify our hypotheses in terms of AS-level tolerance we conduct a longitudinal analysis over 3.8M malicious events triggered by IoT botnets across over 8K ASes using measurements gathered through globally distributed honeypots, IP blacklists and Internet regional registries for a three year period. We argue that the findings in the herein work can greatly benefit a range of stakeholders designing, operating, and managing current defense mechanisms as well as contributing significantly towards the evolution of next generation cyber defense mechanisms.
Hatem A. Almazarqi, Mathew Woodyard, Angelos K. Marnerides
ICC3
2024 Sizzler: Sequential Fuzzing in Ladder Diagrams for Vulnerability Detection and Discovery in Programmable Logic Controllers
abstract
Programmable Logic Controllers (PLCs) constitute the basis of Industrial Control Systems (ICSs) underpinning sectors ranging from nuclear, up to energy and manufacturing. Currently, PLC vulnerability assessment practices employed by ICS operators are limited due to their reliance on empirical observations of visible code crashes prompted by PLC compilers. In parallel, the prevalent PLC firmware dependency on proprietary vendor routines restricts the composition of generic vulnerability detection or discovery schemes for zero-day threat vectors. In this work, we propose Sizzler: a novel vendor-independent vulnerability discovery framework specific to PLC applications operating with logic realised through ladder diagrams. Sizzler extends the current state of the art by proposing the optimal synergy of a mutation-based fuzzing strategy using Sequential Generative Adversarial Network (SeqGAN). By virtue of critical vendor restrictions on emulating PLC firmware, we also refine the Quick Emulator (QEMU)’s General Purpose I/O (GPIO) and the Inter-Integrated Circuit (I2C) protocols to evaluate and compare Sizzler across 30 PLC ladder diagram programs compiled from LDmicro and OpenPLC projects over five widely used Micro-Controller Units (MCUs). It is noteworthy that Sizzler has successfully identified vulnerabilities in ladder diagrams within a relatively short time frame based on our proprietary dataset and secured a CVE-ID. Moreover, through a comparison of Sizzler with prevalent fuzzing techniques over the commonly used Magma and LAVA-M datasets we exhibit its wider applicability on embedded systems and identify its limitations.
Marco M. Cook, Angelos K. Marnerides
IEEE Trans. Inf. Forensics Secur.3
2024 Adaptive Energy Theft Detection in Smart Grids Using Self-Learning With Dual Neural Network
abstract
Energy theft is an extremely prominent challenge causing significant energy and revenue losses for utility providers worldwide. The introduction of advanced metering infrastructures consisting of smart meter deployments has undeniably extended the attack surface, enabling individual consumers or prosumers to trigger composite energy theft attack vectors. In this work, we introduce an energy theft detection system capable of distinguishing properties of power consumption and generation theft with possible misconfigurations caused by nonmalicious intent. The proposed approach is adaptive through a self-learning operation that is updated continuously as new measurements become available. With the synergistic use of measurements collected by real PV installations and openly available weather information, the system achieves high accuracy and precision result in theft identification over streamed data measurements. Thus, it promotes low computational costs and its architecture can be easily integrated within smart grid infrastructures to realize next-generation cross-batch energy theft detection.
Ahlam Althobaiti, Charalampos Rotsos, Angelos K. Marnerides
IEEE Trans. Ind. Informatics3
2023 Tracking IoT P2P Botnet Loaders in the Wild
abstract
Evidently, centralised botnets are nowadays considered as easy targets for take-down efforts by law enforcement and computer security researchers. Hence, malicious actors transitioned towards the implementation of Peer-to-Peer (P2P) IoT botnets such to solidify their infrastructures, avoid single points of failure and further evade back tracking. Consequently, due to the highly distributed persona of modern P2P botnets, the detection of critical nodes to aid for the effective capturing of emerging threat vectors in such setups evolved into a challenging task. In this work, we conduct a novel 24-month longitudinal study based on real Internet measurements from globally distributed honeypots focusing on propagation trends of P2P IoT botnets. In order to achieve this, we develop graph-based centrality metrics to attribute AS-level connectivity characteristics to botnet and malware propagation as well as relating AS-level tolerance for botnet malware hosts we refer to as loaders. In general, we argue that the proposed methodology and outcomes of the herein study, can significantly benefit security experts and network operators towards the design of mitigation measures against present and future P2P botnets.
Hatem A. Almazarqi, Mathew Woodyard, Troy Mursch, Dimitrios P. Pezaros, Angelos K. Marnerides
ICC5
2023 PLCPrint: Fingerprinting Memory Attacks in Programmable Logic Controllers
abstract
Programmable Logic Controllers (PLCs) constitute the functioning basis of Industrial Control Systems (ICS) and hence are often a focal point for attackers to exploit. Previous attacks have seen PLC memory maliciously altered in order to disrupt the underlying physical process. Different types of memory attack can cause a similar impact on the PLC’s operation and result in indistinguishable physical manifestations. Consequently, delays in triaging attacks through digital forensic practices can induce significant financial loss, physical damage to the infrastructure, and degradation of safety. In this work, we propose PLCPrint, a novel vendor-independent fingerprinting approach that utilises PLC memory artefacts to perform detection and classification of memory attacks. PLCPrint uses PLC memory register mapping, a novel method exploiting the relationship between PLC registers and memory artefacts including the PLC application code. Through this, registers are assigned a Mapping Condition (MC) to indicate how they exist within the PLC memory artefacts. We evaluate the performance of PLCPrint over realistic emulations conducted at a real testbed emulating water filtration and distribution. Through PLCPrint we depict how MC deviations are utilised within supervised learning schemes such as to adequately classify PLC memory attacks with high accuracy performance. In general, we demonstrate that PLCPrint fills the gap in the context of attack technique triaging since this has been a missing element within current ICS forensics schemes.
Marco M. Cook, Angelos K. Marnerides, Dimitrios P. Pezaros
IEEE Trans. Inf. Forensics Secur.2
2022 Macroscopic Analysis of IoT Botnets
abstract
The adoption of the IoT by modern sociotechnical systems in synergy with the rapid deployment of insecure IoT devices and services has transformed the cyber-threat landscape. Thus, the vast majority of cyberattacks are underpinned by the orchestration of compromised IoT devices that are globally distributed and controlled through carefully designed IoT botnets. Contrary to conventional belief, cybersecurity vectors instrumented by such botnets are not always uniformly distributed across Internet Autonomous Systems (ASes). By virtue of network structural characteristics imposed by each individual Autonomous System (AS) as well as the diversity in terms of AS-level cybersecurity policies, the spatiotemporal manifestation of IoT botnets differs. In this work, we provide a novel measurement study that empirically quantifies AS tolerance of IoT botnet propagation in the global IPv4 Internet. We assess and correlate measurements gathered by globally distributed honeypots, Internet regional registries and IP blacklists for a 15-month period and observe more than 3.2M malicious events triggered by IoT botnets spanning 9.5K ASes. Our work demonstrates that ASes connected to a low number of providers are prone to embrace a high portion of malicious activities. Hence, we provide evidence on concentrated botnet activities and determine the effectiveness of widely used IP blacklists. In general, this study contributes towards empowering knowledge on large-scale cyber-attacks as being crucial for the composition of next generation data-driven cybersecurity defence applications.
Hatem A. Almazarqi, Mathew Woodyard, Troy Mursch, Dimitrios P. Pezaros, Angelos K. Marnerides
GLOBECOM5
2022 Anomaly Diagnosis in Cyber-Physical Systems
abstract
Cyber-Physical Systems (CPS) constitute the operational basis for a number of critical national infrastructure (CNI) sectors including but not limited to manufacturing, smart electrical grids and water utilities, where programmable networked systems enable physical processes. Programmable Logic Controllers (PLCs) play a vital role in this by controlling CPS processes and consequently have become a primary target for cyber attacks that aim to disrupt CPS. By contrast with conventional networked setups, the operational and safety-critical importance of PLCs introduce challenges for CNI operators on empirically determining if an incident is a cyber-attack or a system fault as both occurrences can display similar outputs on the physical process. Moreover, existing anomaly detection techniques explicit to PLCs primarily give indication of an incident rather than attempting to categorise what the incident is. In this paper, we introduce a novel PLC anomaly diagnosis framework defined by a two-stage identification and classification approach based on novelty detection. Through the use of PLC run-time and network communication data generated by physical processes on a representational CPS testbed, we achieve an average of 99.35% on anomaly profiling accuracy and highlight the distinctions between system faults and cyber-attacks. In general, we demonstrate a practical approach that can be adopted by next generation CPS cyber defence tools.
Marco M. Cook, Cory Paterson, Angelos K. Marnerides, Dimitrios P. Pezaros
ICC3
2022 Practical Intrusion Detection of Emerging Threats
abstract
The Internet of Things (IoT), in combination with advancements in Big Data, communications and networked systems, offers a positive impact across a range of sectors including health, energy, manufacturing and transport. By virtue of current business models adopted by manufacturers and ICT operators, IoT devices are deployed over various networked infrastructures with minimal security, opening up a range of new attack vectors. Conventional rule-based intrusion detection mechanisms used by network management solutions rely on pre-defined attack signatures and hence are unable to identify new attacks. In parallel, anomaly detection solutions tend to suffer from high false positive rates due to the limited statistical validation of ground truth data, which is used for profiling normal network behaviour. In this work we go beyond current solutions and leverage the coupling of anomaly detection and Cyber Threat Intelligence (CTI) with parallel processing for the profiling and detection of emerging cyber attacks. We demonstrate the design, implementation, and evaluation ofCitrus: a novel intrusion detection framework which is adept at tackling emerging threats through the collection and labelling of live attack data by utilising diverse Internet vantage points in order to detect and classify malicious behaviour using graph-based metrics as well as a range of machine learning (ML) algorithms. Citrus considers the importance of ground truth data validation and its flexible software architecture enables both the real-time and offline profiling, detection and classification of emerging cyber-attacks under optimal computational costs. Thus, establishing it as a viable and practical solution for next generation network defence and resilience strategies.
Ryan Mills, Angelos K. Marnerides, Matthew Broadbent, Nicholas J. P. Race
IEEE Trans. Netw. Serv. Manag.2
2021 Profiling IoT Botnet Activity in the Wild
abstract
Undoubtedly, the Internet of Things (IoT) contributes significantly to daily mission-critical processes underpinning a number of socio-technical systems. Conversely, its rapid adoption has extensively broadened the cyber-threat landscape by virtue of low-cost IoT devices that are manufactured and deployed with minimal security. Evidently, vulnerable IoT devices are utilised by attackers to participate into Internet-wide botnets in order to instrument large-scale cyber-attacks and disrupt critical Internet services. Since the 2016 outbreak of the first IoT Mirai botnet there has been a continuous evolution of Mirai-like variants. Tracking these botnets is challenging due to their varying structural characteristics, and also due to the fact that malicious actors continuously adopt new evasion and propagation strategies. This work provides a new measurement study highlighting specific behavioural properties of Mirai-like botnets in terms of their propagation. We provide a comprehensive analysis conducted on real Cyber Threat Intelligence (CTI) feeds gathered for a period of 7 months from globally distributed attack honeypots and pinpoint the evolutionary port scanning patterns, targeted vulnerabilities and preferred services pursued by Mirai-like botnets. We identify the most frequently active Mirai-like malware binaries and we are the first to report the evolution of a new, P2P-based variant. In parallel, we provide evidence related to the lack of vendor-specific patching through highlighting unpatched vulnerabilities. Moreover, we pinpoint the inadequacy of widely used IP blacklisting databases to timely list malicious IP addresses. Thus, arguing in fair of integrating honeypot information from diverse Internet vantage points within the design of next generation botnet defence mechanisms.
Hatem A. Almazarqi, Angelos K. Marnerides, Troy Mursch, Mathew Woodyard, Dimitrios P. Pezaros
GLOBECOM2
2020 Fast and Furious: Outrunning Windows Kernel Notification Routines from User-Mode
Pierre Ciholas, Jose M. Such, Angelos K. Marnerides, Benjamin Green 0001, Utz Roedig
DIMVA3
2020 SCADA-agnostic Power Modelling for Distributed Renewable Energy Sources
abstract
Distributed Renewable Energy Sources (DRES) are considered as instrumental within modern smart grids and more broadly to the various ancillary services contained within the energy trading market. Thus, the adequate power production profiling and forecasting of DRES deployments is of vital importance such as to support various grid optimisation and accounting processes. The variety of DRES in stallation companies in conjunction with the diversity of ownership on DRES machinery, controller firmware and Supervisory Control and Data Acquisition (SCADA) software leads to cases where centralised SCADA measurements are not entirely available or are provided under a subscription-based model. In this work, we consider this pragmatic scenario and introduce a SCADA-agnostic approach that utilises freely available weather measurements for explicitly profiling and forecasting power generation as produced in real wind turbine deployments. For this purpose, we leverage various machine learning (ML) libraries to demonstrate the applicability of our system and further compare it with forecasting outputs obtained when using SCADA measurements. Through this study, we demonstrate a viable and exogenous profiling solution achieving similar accuracy with SCADA-based schemes under much lower computational costs.
Ahlam Althobaiti, Anish Jindal, Angelos K. Marnerides
WoWMoM3
2020 Encrypted video traffic clustering demystified
Amit Dvir, Angelos K. Marnerides, Ran Dubin, Nehor Golan, Chen Hajaj
Comput. Secur.2
2019 Profiling IoT-Based Botnet Traffic Using DNS
abstract
Internet-wide security and resilience have traditionally been subject to large-scale DDoS attacks initiated by various types of botnets. Since the Mirai outbreak in 2016 myriads of Mirai-alike IoT-based botnets have emerged. Such botnets rely on Mirai's base malware code and they infiltrate vulnerable IoT devices on an Internet-wide scale such as to instrument them to perform large-scale attacks such as DDoS. As recently shown, DDoS attacks triggered by Mirai-alike IoT-based botnets go far beyond traditional pre-2016 DDoS attacks since they have a much higher amplification and their propagation is far more aggressive. Thus, it is of crucial importance to tailor botnet detection schemes accordingly. This work provides a novel DNS-based profiling scheme over real datasets of Mirai-alike botnet activity captured on honeypots that are globally distributed. We firstly discuss features used in profiling botnets in the past and indicate how profiling IoT-based botnets in particular can be improved by leveraging DNS information out of a single DNS record. We further conduct an evaluation of our developed feature set over various Machine Learning (ML) classifiers and demonstrate the applicability of our scheme. Our resulted outputs indicate that the proposed feature set can significantly reduce botnet detection time whilst simultaneously maintaining high levels of accuracy of 99% on average under the random forest formulation.
Owen P. Dwyer, Angelos K. Marnerides, Vasileios Giotsas, Troy Mursch
GLOBECOM2
2019 Communication Standards for Distributed Renewable Energy Sources Integration in Future Electricity Distribution Networks
abstract
Distributed Renewable Energy Sources (DRESs) such as wind and solar are becoming a promising alternative for the energy supply in modern (smart) electricity grids as part of future sustainable smart cities. Successful integration of DRESs requires efficient, resilient, and secure communication in order to satisfy the highly challenging and real-time constraints of smart city applications. Regardless of the various research solutions proposed in this context within the last decade, the relevant standardization is a non-trivial issue and is still in its infancy. In this position paper, we briefly review the currently employed DRES communications standards and identify the gaps in their present status. Finally, we discuss and suggest potential pathways for further improvement.
Anish Jindal, Angelos K. Marnerides, Antonios Gouglidis, Andreas Mauthe, David Hutchison 0001
ICASSP2
2019 Improved Network Traffic Classification Using Ensemble Learning
abstract
Despite the large number of research efforts that applied specific machine learning algorithms for network traffic classification, recent work has highlighted limitations and particularities of individual algorithms that make them more suitable to specific types of traffic and scenarios. As such, an important topic in this area is how to combine individual algorithms using meta-learning techniques in order to obtain more robust traffic classification metrics. This paper presents a comparative analysis among meta-learning approaches and individual classifiers to classify network traffic. We investigate and evaluate a range of meta-learning techniques, including Voting, Stacking, Bagging and Boosting. We then propose a new experimental analysis of different meta-learning techniques - also known as ensemble learners- and compare them with their own base classifiers when used individually. Finally, considering the emerging popularity of Neural Networks, we analyze this scenario using the Multi-layer Perceptron classifier. The experiments were performed with data provided by the UCI Machine Learning Repository. The best performance was obtained by an ensemble technique (Bagging), which obtained accuracy of 99.972% and false positive rate of 0.00018%.
Isadora P. Possebon, Anderson Santos da Silva, Lisandro Z. Granville, Alberto E. Schaeffer Filho, Angelos K. Marnerides
ISCC5
2018 Internet traffic characterisation: Third-order statistics & higher-order spectra for precise traffic modelling
abstract
Undoubtedly, the characterisation of network traffic flows is vitally important in understanding the dynamics of Internet traffic and in appropriately dimensioning network resources for network and systems management. The vast majority of modelling techniques developed for volume-based traffic profiling (based on packet and/byte counts) imply the statistical assumptions of stationarity, Gaussianity and linearity, which are often taken for granted without being explicitly validated. In this paper, we demonstrate that such properties are often not applicable due to the high fluctuations in Internet traffic, and should therefore be validated first before they are assumed. We employ Time-Frequency (TF) representations and the Hinich algorithms for validating these three modelling assumptions on real backbone and edge network traces. We show by conducting a passive, offline statistical analysis on real operational network traffic traces from both backbone and edge links that link traffic is extremely dynamic irrespective of the level of aggregation and that model characteristics vary. Subsequently, we propose the use of a representative of higher order spectra, the bispectrum, to act as a particularly suitable method for volume-based traffic profiling due to its ability to adapt to different underlying statistical assumptions, as opposed to ARIMA timeseries models that have been typically used in the literature. We demonstrate that the bispectrum, a signal processing tool that has so far been used in the area of image processing and acoustic signals, can be exploited to accurately characterise traffic volumes per transport protocol, and can therefore contribute to fine-grained network operations tasks such as application classification and anomaly detection.
Angelos K. Marnerides, Dimitrios P. Pezaros, David Hutchison 0001
Comput. Networks1
2018 An Inter-Domain Collaboration Scheme to Remedy DDoS Attacks in Computer Networks
abstract
Distributed denial-of-service (DDoS) attacks continue to trouble network operators and service providers, and with increasing intensity. Effective response to DDoS can be slow (because of manual diagnosis and interaction) and potentially self-defeating (as indiscriminate filtering accomplishes a likely goal of the attacker), and this is the result of the discrepancy between the service provider's flow-based, application-level view of traffic and the network operator's packet-based, network-level view and limited functionality. Furthermore, a network required to take action may be in an autonomous system (AS) several AShops away from the service, so it has no direct relationship with the service on whose behalf it acts. This paper presents Antidose, a means of interaction between a vulnerable peripheral service and an indirectly related AS that allows the AS to confidently deploy local filtering with discrimination under the control of the remote service. We implement the core filtering mechanism of antidose, and provide an analysis of it to demonstrate that conscious attacks against the mechanism will not expose the AS to additional attacks. We present a performance evaluation to show that the mechanism is operationally feasible in the emerging trend of operators' willingness to increase the programmability of their hardware with SDN technologies such as OpenFlow, as well as to act to mitigate attacks on downstream customers.
Steven Simpson, Noor-ul-Hassan Shirazi, Angelos K. Marnerides, Simon Jouet, Dimitrios P. Pezaros, David Hutchison 0001
IEEE Trans. Netw. Serv. Manag.3
2017 Multi-level resilience in networked environments: Concepts & principles
abstract
Resilience is an essential property for critical networked environments such as utility networks (e.g. gas, water and electricity grids), industrial control systems, and communication networks. Due to the complexity of such networked environments achieving resilience is multi-dimensional since it involves a range of factors such as redundancy and connectivity of different system components as well as availability, security, dependability and fault tolerance. Hence, it is of importance to address resilience within a unified framework that considers such factors and further enables the practical composition of resilience mechanisms. In this paper we firstly introduce the concepts and principles of Multi-Level Resilience (MLR) and then demonstrate its applicability in a particular cloud-based scenario.
Muhammad Azizi Mohd Ariffin, Angelos K. Marnerides, Andreas Mauthe
CCNC2
2017 A programmable SDN+NFV-based architecture for UAV telemetry monitoring
abstract
The explosive growth in the worldwide use of Unmanned Aerial Vehicles (UAVs) has raised a critical concern with respect to the adequate management of their ad hoc network configuration as required by their mobility management process. As UAVs migrate among ground control stations, associated network services, routing and operational control must also rapidly migrate to ensure a seamless transition. In this paper, we present a novel, lightweight and modular architecture which supports high mobility and situational-awareness through the application of Software Defined Networking (SDN) and Network Function Virtualization (NFV) principles on top of the UAV infrastructure. By combining SDN+NFV programmability we can achieve a robust migration of UAV-related network services, such as network monitoring and anomaly detection as well as smooth UAV migration that confronts high mobility requirements. The proposed container-based monitoring and anomaly detection Network Functions (NFs) as employed within our architecture can be tuned to specific UAV types providing operators better insight during live, high-mobility deployments. We evaluate our architecture against telemetry from over 80 flights from a scientific research UAV infrastructure showing our ability to tune and detect emerging challenges.
Kyle J. S. White, Ewen Denney, Matt D. Knudson, Angelos K. Marnerides, Dimitrios P. Pezaros
CCNC4
2017 Distributed, multi-level network anomaly detection for datacentre networks
abstract
Over the past decade, numerous systems have been proposed to detect and subsequently prevent or mitigate security vulnerabilities. However, many existing intrusion or anomaly detection solutions are limited to a subset of the traffic due to scalability issues, hence failing to operate at line-rate on large, high-speed datacentre networks. In this paper, we present a two-level solution for anomaly detection leveraging independent execution and message passing semantics. We employ these constructs within a network-wide distributed anomaly detection framework that allows for greater detection accuracy and bandwidth cost saving through attack path reconstruction. Experimental results using real operational traffic traces and known network attacks generated through the Pytbull IDS evaluation framework, show that our approach is capable of detecting anomalies in a timely manner while allowing reconstruction of the attack path, hence further enabling the composition of advanced mitigation strategies. The resulting system shows high detection accuracy when compared to similar techniques, at least 20% better at detecting anomalies, and enables full path reconstruction even at small-to-moderate attack traffic intensities (as a fraction of the total traffic), saving up to 75% of bandwidth due to early attack detection.
Mircea Iordache, Simon Jouet, Angelos K. Marnerides, Dimitrios P. Pezaros
ICC3
2017 Modeling Server Workloads for Campus Email Traffic Using Recurrent Neural Networks
Spyros Boukoros, Anupiya Nugaliyadde, Angelos K. Marnerides, Costas Vassilakis 0001, Polychronis Koutsakis, Kevin Kok Wai Wong
ICONIP (5)3
2017 Uncertainty-driven ensemble forecasting of QoS in Software Defined Networks
abstract
Software Defined Networking (SDN) is the key technology for combining networking and Cloud solutions to provide novel applications. SDN offers a number of advantages as the existing resources can be virtualized and orchestrated to provide new services to the end users. Such a technology should be accompanied by powerful mechanisms that ensure the end-to-end quality of service at high levels, thus, enabling support for complex applications that satisfy end users needs. In this paper, we propose an intelligent mechanism that agglomerates the benefits of SDNs with real-time “Big Data” forecasting analytics. The proposed mechanism, as part of the SDN controller, supports predictive intelligence by monitoring a set of network performance parameters, forecasting their future values, and deriving indications on potential service quality violations. By treating the performance measurements as time-series, our mechanism employs a novel ensemble forecasting methodology to estimate their future values. Such predictions are fed to a Type-2 Fuzzy Logic system to deliver, in real-time, decisions related to service quality violations. Such decisions proactively assist the SDN controller for providing the best possible orchestration of the virtualized resources. We evaluate the proposed mechanism w.r.t. precision and recall metrics over synthetic data.
Kostas Kolomvatsos, Christos Anagnostopoulos 0001, Angelos K. Marnerides, Qiang Ni, Stathes Hadjiefthymiades, Dimitrios P. Pezaros
ISCC3
2016 Secure and privacy-aware proxy mobile IPv6 protocol for vehicle-to-grid networks
abstract
Vehicle-to-Grid (V2G) networks have emerged as a new communication paradigm between Electric Vehicles (EVs) and the Smart Grid (SG). In order to ensure seamless communications between mobile EVs and the electric vehicle supply equipment, the support of ubiquitous and transparent mobile IP communications is essential in V2G networks. However, enabling mobile IP communications raises real concerns about the possibility of tracking the locations of connected EVs through their mobile IP addresses. In this paper, we employ certificate-less public key cryptography in synergy with the restrictive partially blind signature technique to construct a secure and privacy-aware proxy mobile IPv6 (SP-PMIPv6) protocol for V2G networks. SP-PMIPv6 achieves low authentication latency while protecting the identity and location privacy of the mobile EV. We evaluate the SP-PMIPv6 protocol in terms of its authentication overhead and the information-theoretic uncertainty derived by the mutual information metric to show the high level of achieved anonymity.
Max Eiza, Qi Shi 0001, Angelos K. Marnerides, Thomas J. Owens
ICC3
2016 Malware Detection in Cloud Computing Infrastructures
abstract
Cloud services are prominent within the private, public and commercial domains. Many of these services are expected to be always on and have a critical nature; therefore, security and resilience are increasingly important aspects. In order to remain resilient, a cloud needs to possess the ability to react not only to known threats, but also to new challenges that target cloud infrastructures. In this paper we introduce and discuss an online cloud anomaly detection approach, comprising dedicated detection components of our cloud resilience architecture. More specifically, we exhibit the applicability of novelty detection under the one-class support Vector Machine (SVM) formulation at the hypervisor level, through the utilisation of features gathered at the system and network levels of a cloud node. We demonstrate that our scheme can reach a high detection accuracy of over$90$percent whilst detecting various types of malware and DoS attacks. Furthermore, we evaluate the merits of considering not only system-level data, but also network-level data depending on the attack type. Finally, the paper shows that our approach to detection using dedicated monitoring components per VM is particularly applicable to cloud scenarios and leads to a flexible detection system capable of detecting new malware strains with no prior knowledge of their functionality or their underlying instructions.
Michael R. Watson, Noor-ul-Hassan Shirazi, Angelos K. Marnerides, Andreas Mauthe, David Hutchison 0001
IEEE Trans. Dependable Secur. Comput.3
2015 SDN-PANDA: Software-Defined Network Platform for ANomaly Detection Applications
abstract
The proliferation of cloud-enabled services has caused an exponential growth in the traffic volume of modern data centres (DCs). An important aspect for the optimal operation of DCs related to the real-time detection of anomalies within the measured traffic volume in order to identify possible threats or challenges that are caused by either malicious or legitimate intent. Therefore in this paper we present SDN-PANDA, a 'pluggable' software platform that aims to provide centralised administration and experimentation for anomaly detection techniques in Software Defined Data Centres (SDDCs). We present the overall design of the proposed scheme, and illustrate some initial results related to the performance of the current prototype with respect to scalability and basic traffic visualisation. We argue that the introduced platform may facilitate the underlying functional basis for a number of real-time anomaly detection applications and provide the necessary foundations for such algorithms to be easily deployed.
Brian R. Granby, Robert Askwith, Angelos K. Marnerides
ICNP3
2015 A multi-level resilience framework for unified networked environments
abstract
Networked infrastructures underpin most social and economical interactions nowadays and have become an integral part of the critical infrastructure. Thus, it is crucial that heterogeneous networked environments provide adequate resilience in order to satisfy the quality requirements of the user. In order to achieve this, a coordinated approach to confront potential challenges is required. These challenges can manifest themselves under different circumstances in the various infrastructure components. The objective of this paper is to present a multi-level resilience approach that goes beyond the traditional monolithic resilience schemes that focus mainly on one infrastructure component. The proposed framework considers four main aspects, i.e. users, application, network and system. The latter three are part of the technical infrastructure while the former profiles the service user. Under two selected scenarios this paper illustrates how an integrated approach coordinating knowledge from the different infrastructure elements allows a more effective detection of challenges and facilitates the use of autonomic principles employed during the remediation against challenges.
Angelos K. Marnerides, Akshay Bhandari, Hema A. Murthy, Andreas Mauthe
IM1
2015 Tool support for the evaluation of anomaly traffic classification for network resilience
abstract
Resilience is the ability of the network to maintain an acceptable level of operation in the face of anomalies, such as malicious attacks, operational overload or misconfigurations. Techniques for anomaly traffic classification are often used to characterize suspicious network traffic, thus supporting anomaly detection schemes in network resilience strategies. In this paper, we extend the PReSET toolset to allow the investigation, comparison and analysis of algorithms for anomaly traffic classification based on machine learning. PReSET was designed to allow the simulation-based evaluation of resilience strategies, thus enabling the comparison of optimal configurations and policies for combating different types of attacks (e.g., DDoS attacks, worms) and other anomalies. In such resilience strategies, policies written in the Ponder2 language can be used to activate/reconfigure traffic classification modules and other mechanisms (e.g., traffic shaping), depending on monitored results in the simulation environment. Our results show that PReSET can be a valuable tool for network operators to evaluate anomaly traffic classification techniques in terms of standard performance metrics.
Anderson Santos da Silva, Juliano Araújo Wickboldt, Alberto E. Schaeffer Filho, Angelos K. Marnerides, Andreas Mauthe
ISCC4
2015 Fault diagnosis in DSL networks using support vector machines
Angelos K. Marnerides, Simon Malinowski, Ricardo Morla, Hyong S. Kim 0001
Comput. Commun.1
2014 Traffic anomaly diagnosis in Internet backbone networks: A survey
Angelos K. Marnerides, Alberto E. Schaeffer Filho, Andreas Mauthe
Comput. Networks1
2013 Internet traffic classification using energy time-frequency distributions
abstract
We present a fundamentally new approach to classify application flows based on the mapping of aggregate transport-layer volume information onto the Time-Frequency (TF) plane. We initially show that the volume persona (i.e. counts of packets and bytes) of traffic flows at the transport layer exhibits highly non-stationary characteristics, hence rendering many typical classification methods inapplicable. By virtue of this constraint, we present a novel application classification method based on the Cohen energy TF distributions for such highly non-stationary signals. We have used the Rényi information to measure the distinct complexity of any given application signal, and to subsequently construct a robust training model for every application protocol within our scheme. The effectiveness of our approach is demonstrated using real backbone and edge link network traces captured in US and Japan. Our results show that for the majority of applications, aggregate volume-based classification can reach up to 96% accuracy, while considering significantly less features in comparison with existing approaches.
Angelos K. Marnerides, Dimitrios P. Pezaros, David Hutchison 0001
ICC1
2013 On the comprehension of DSL SyncTrap events in IPTV networks
abstract
The adequate operation of IPTV distribution networks heavily relies on the effective maintenance and management of their underlay DSL infrastructure. New hardware and software is required in order to improve monitoring capabilities and to directly diagnose anomalies that other segments of the DSL network cannot identify. In this work we initially compare the accuracy performance of SVM-specific formulations for constructing a robust ground truth within our classification procedure regarding abnormalities issued at anomaly-aware Digital Subscriber Line Access Multiplexers (DSLAMs) of the DSL infrastructure. Moreover, we consider the pragmatic cost of repairing anomalies that were misclassified and characterize each classifier according to the overall cost that is possible to incur to the network operator. In parallel, this work attempts to practically improve the network-wide anomaly classification performance by proposing a semi-supervised classification scheme that updates the initial supervised scheme by testing unlabelled anomalies occurring at anomaly-unaware DSLAMs.
Angelos K. Marnerides, Simon Malinowski, Ricardo Morla, Miguel R. D. Rodrigues, Hyong S. Kim 0001
ISCC1
2012 Towards the improvement of diagnostic metrics Fault diagnosis for DSL-Based IPTV networks using the Rényi entropy
abstract
IPTV networks blindly rely on the adequate operation and management of the underlying infrastructure that in numerous cases is threaten by unexpected anomalous events which consequently cause QoS degradation to the end-user. Thus, it is of great importance to deploy techniques embodied with diagnostic and self-protection metrics for determining and predicting the arrival of such events in order to proactively charge defense mechanisms without the need of an exhaustive manual inspection by the network operator. In this paper we propose and demonstrate the applicability of the Rényi entropy as a useful diagnosis feature for explicitly characterizing DSL-level anomalies issued in an IPTV network of a large European ISP. It is revealed that different orders of the Rényi entropy can formulate meaningful detection and categorization of phenomena occurring on specific Digital Subscriber Line Access Multiplexers (DSLAMs) within the DSL infrastructure. Via the synergistic exploitation of the local maxima peaks generated by each Rényi-based distribution we exhibit the feasibility to extract and identify lightweight anomalies that under simple metrics cannot be detected.
Angelos K. Marnerides, Simon Malinowski, Ricardo Morla, Miguel R. D. Rodrigues, Hyong S. Kim 0001
GLOBECOM1
2010 Autonomic diagnosis of anomalous network traffic
abstract
Network traffic abnormalities pose one of the greatest threats for networked environments. Autonomic communications offer a solution: it should be possible to design network mechanisms that behave adaptively and respond to any anomalous phenomenon that threatens normal network behaviour. In this paper we present the design of an adaptive anomaly detection component that has been built as part of an autonomic network system. We have implemented an entropy estimator to predict the onset of anomalous traffic behaviour within an autonomic resilience framework, and a Supervised Naive Bayesian classifier which synergistically empower the core properties of self-adaptation, self-learning and self-protection for next generation networks. Being part of an always-on, automated measurement and control infrastructure, such mechanism enforces the adaptive system reaction to suboptimal network operation and its subsequent restoration, while requiring minimal static (re)configuration and operator intervention.
Angelos K. Marnerides, David Hutchison 0001, Dimitrios P. Pezaros
WOWMOM1
2008 Detection and mitigation of abnormal traffic behaviour in autonomic networked environments
abstract
Autonomic network environments are required to be resilient. Resilience is defined as the ability for a network to provide and maintain an acceptable level of service in the face of various challenges to normal operation [1]. Traffic abnormalities are a great challenge and it is vital for any network to be supported by resilient mechanisms in order to detect and mitigate such events. In this document we present our measurement-based resilience architecture and we argue that the correct combination of already proposed theoretical methodologies and mechanisms present in our architecture compose a powerful defence mechanism that satisfies autonomic properties such as self-protection and self-optimization. In addition we refer to our intentions of testing our proposed architecture within the ANA project [2] in order to justify our hypothesis.
Angelos K. Marnerides, Dimitrios P. Pezaros, David Hutchison 0001
CoNEXT1