{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/98264"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/98264","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Site reliability against anomalous behaviors","abstract":"Many attacks that threaten service providers and legitimate users are anomalous behaviors out of specification, and this dissertation mainly focuses on detecting “large” Internet flows consuming more resources than those allocated to them. Being able to identify large flows accurately can greatly benefit Quality of Service (QoS) schemes and Distributed Denial of Service (DDoS) defenses. Although large-flow detection has been previously explored, proposed approaches have not been practical for high-capacity core routers due to high memory and processing overhead. Additionally, more efficient schemes are vulnerable against specially tailored attacks in which attackers time their packets based on the knowledge of legitimate cross-traffic. In this dissertation, we aim to design computation- and memory-efficient large-flow detection algorithms to effectively mitigate the large-flow damage in adversarial environments. We propose three large-flow detection schemes: Exact-Outside-Ambiguity-Region Detector (EARDet), Recursive Large-Flow Detection (RLFD), and the scheme of in-Core Limiting of Egregious Flows (CLEF), which is a hybrid scheme with one EARDet and two RLFDs. EARDet is a deterministic algorithm that guarantees exact large-flow detection outside an ambiguity region: there is no false accusation for legitimate flows complying with a low-bandwidth threshold, and no false negative for large flows above a high-bandwidth threshold, with no assumption on the input traffic or attack patterns. Because of the strong enforcement with the arbitrary window model, EARDet is able to immediately detect both flat and bursty flows. RLFD is designed to complement EARDet in detecting large flows in EARDet’s ambiguity region. RLFD is a probabilistic detection scheme that gives higher probability for detecting large flows with higher volume, thus guarantee limited damage (to legitimate flows) across a wide range of flow overuse amounts. Finally CLEF combines EARDet and RLFD to achieve both rapid detection for very large flows and eventually detection for small, persistent large flows. Theoretical analysis and experimental evaluation both suggest the CLEF’s efficiency and effectiveness outperform existing algorithms.","abstract_html":"Many attacks that threaten service providers and legitimate users are anomalous behaviors out of specification, and this dissertation mainly focuses on detecting “large” Internet flows consuming more resources than those allocated to them. Being able to identify large flows accurately can greatly benefit Quality of Service (QoS) schemes and Distributed Denial of Service (DDoS) defenses. Although large-flow detection has been previously explored, proposed approaches have not been practical for high-capacity core routers due to high memory and processing overhead. Additionally, more efficient schemes are vulnerable against specially tailored attacks in which attackers time their packets based on the knowledge of legitimate cross-traffic. In this dissertation, we aim to design computation- and memory-efficient large-flow detection algorithms to effectively mitigate the large-flow damage in adversarial environments. We propose three large-flow detection schemes: Exact-Outside-Ambiguity-Region Detector (EARDet), Recursive Large-Flow Detection (RLFD), and the scheme of in-Core Limiting of Egregious Flows (CLEF), which is a hybrid scheme with one EARDet and two RLFDs. EARDet is a deterministic algorithm that guarantees exact large-flow detection outside an ambiguity region: there is no false accusation for legitimate flows complying with a low-bandwidth threshold, and no false negative for large flows above a high-bandwidth threshold, with no assumption on the input traffic or attack patterns. Because of the strong enforcement with the arbitrary window model, EARDet is able to immediately detect both flat and bursty flows. RLFD is designed to complement EARDet in detecting large flows in EARDet’s ambiguity region. RLFD is a probabilistic detection scheme that gives higher probability for detecting large flows with higher volume, thus guarantee limited damage (to legitimate flows) across a wide range of flow overuse amounts. Finally CLEF combines EARDet and RLFD to achieve both rapid detection for very large flows and eventually detection for small, persistent large flows. Theoretical analysis and experimental evaluation both suggest the CLEF’s efficiency and effectiveness outperform existing algorithms.","abstract_has_math":false,"creators":["Wu, Hao"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Hu, Yih-Chun","Borisov, Nikita","Bailey, Michael","Hsiao, Hsu-Chun"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2017,"date_issued":"2017-09-29T16:39:23Z","date_published":"2017-09-29T16:39:23Z","updated_at":"2026-07-22T22:24:35Z","subjects":["Large-flow detection","Damage metric","Memory and computation efficiency"],"languages":["en"],"rights":["Copyright 2017 Hao Wu"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/98264","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Hu, Yih-Chun","Borisov, Nikita","Bailey, Michael","Hsiao, Hsu-Chun"]},{"key":"dc:creator","label":"Author","values":["Wu, Hao"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2017-09-29T16:39:23Z","2017-07-10","2017-08"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Large-flow detection","Damage metric","Memory and computation efficiency"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2017 Hao Wu"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/98264"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Many attacks that threaten service providers and legitimate users are anomalous behaviors out of specification, and this dissertation mainly focuses on detecting “large” Internet flows consuming more resources than those allocated to them. Being able to identify large flows accurately can greatly benefit Quality of Service (QoS) schemes and Distributed Denial of Service (DDoS) defenses. Although large-flow detection has been previously explored, proposed approaches have not been practical for high-capacity core routers due to high memory and processing overhead. Additionally, more efficient schemes are vulnerable against specially tailored attacks in which attackers time their packets based on the knowledge of legitimate cross-traffic. In this dissertation, we aim to design computation- and memory-efficient large-flow detection algorithms to effectively mitigate the large-flow damage in adversarial environments. We propose three large-flow detection schemes: Exact-Outside-Ambiguity-Region Detector (EARDet), Recursive Large-Flow Detection (RLFD), and the scheme of in-Core Limiting of Egregious Flows (CLEF), which is a hybrid scheme with one EARDet and two RLFDs. EARDet is a deterministic algorithm that guarantees exact large-flow detection outside an ambiguity region: there is no false accusation for legitimate flows complying with a low-bandwidth threshold, and no false negative for large flows above a high-bandwidth threshold, with no assumption on the input traffic or attack patterns. Because of the strong enforcement with the arbitrary window model, EARDet is able to immediately detect both flat and bursty flows. RLFD is designed to complement EARDet in detecting large flows in EARDet’s ambiguity region. RLFD is a probabilistic detection scheme that gives higher probability for detecting large flows with higher volume, thus guarantee limited damage (to legitimate flows) across a wide range of flow overuse amounts. Finally CLEF combines EARDet and RLFD to achieve both rapid detection for very large flows and eventually detection for small, persistent large flows. Theoretical analysis and experimental evaluation both suggest the CLEF’s efficiency and effectiveness outperform existing algorithms.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-08-01","The student, Hao Wu, accepted the attached license on 2017-07-10 at 12:18.","The student, Hao Wu, submitted this Dissertation for approval on 2017-07-10 at 12:40.","This Dissertation was approved for publication on 2017-07-10 at 17:31.","DSpace SAF Submission Ingestion Package generated from Vireo submission #11365 on 2017-09-29 at 11:15:00","Made available in DSpace on 2017-09-29T16:39:23Z (GMT). No. of bitstreams: 5 WU-DISSERTATION-2017.pdf: 1628164 bytes, checksum: 3560b43774c77f1933af8a25bdf134e0 (MD5) phd_thesis_src.zip: 17255343 bytes, checksum: fa97ce904e111eba6058d2d8a6e28413 (MD5) LICENSE.txt: 4203 bytes, checksum: 2a1e13ae68aeb9847ee1b3f4f0eb4f5f (MD5) PROQUEST_LICENSE.txt: 4549 bytes, checksum: bdb351d255c1e06d7dc3f73c5712890a (MD5) RightsLink Printable License.pdf: 83836 bytes, checksum: ee9f81a055846739b6b715ab3a67cfa7 (MD5) Previous issue date: 2017-07-10","Embargo set by: Colleen Fallaw for item 103411 Lift date: 2019-09-29T16:39:52Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Colleen Fallaw for item 103411 Lift date: 2019-09-29T17:52:45Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Open Restriction set for Item 103411 on 2018-10-05T17:54:33Z with date null by fschaef2@illinois.edu.","Open Restriction set for Item 103411 on 2018-10-05T17:54:37Z with date null by fschaef2@illinois.edu.","Open Restriction set for Item 103411 on 2018-10-05T17:54:46Z with date null by fschaef2@illinois.edu.","Open Restriction set for Item 103411 on 2018-10-05T17:54:55Z with date null by fschaef2@illinois.edu.","Open"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Site reliability against anomalous behaviors"]}]}],"canonical_facts":{"dc:contributor":["Hu, Yih-Chun","Borisov, Nikita","Bailey, Michael","Hsiao, Hsu-Chun"],"dc:creator":["Wu, Hao"],"dc:date":["2017-09-29T16:39:23Z","2017-07-10","2017-08"],"dc:description":["Many attacks that threaten service providers and legitimate users are anomalous behaviors out of specification, and this dissertation mainly focuses on detecting “large” Internet flows consuming more resources than those allocated to them. Being able to identify large flows accurately can greatly benefit Quality of Service (QoS) schemes and Distributed Denial of Service (DDoS) defenses. Although large-flow detection has been previously explored, proposed approaches have not been practical for high-capacity core routers due to high memory and processing overhead. Additionally, more efficient schemes are vulnerable against specially tailored attacks in which attackers time their packets based on the knowledge of legitimate cross-traffic. In this dissertation, we aim to design computation- and memory-efficient large-flow detection algorithms to effectively mitigate the large-flow damage in adversarial environments. We propose three large-flow detection schemes: Exact-Outside-Ambiguity-Region Detector (EARDet), Recursive Large-Flow Detection (RLFD), and the scheme of in-Core Limiting of Egregious Flows (CLEF), which is a hybrid scheme with one EARDet and two RLFDs. EARDet is a deterministic algorithm that guarantees exact large-flow detection outside an ambiguity region: there is no false accusation for legitimate flows complying with a low-bandwidth threshold, and no false negative for large flows above a high-bandwidth threshold, with no assumption on the input traffic or attack patterns. Because of the strong enforcement with the arbitrary window model, EARDet is able to immediately detect both flat and bursty flows. RLFD is designed to complement EARDet in detecting large flows in EARDet’s ambiguity region. RLFD is a probabilistic detection scheme that gives higher probability for detecting large flows with higher volume, thus guarantee limited damage (to legitimate flows) across a wide range of flow overuse amounts. Finally CLEF combines EARDet and RLFD to achieve both rapid detection for very large flows and eventually detection for small, persistent large flows. Theoretical analysis and experimental evaluation both suggest the CLEF’s efficiency and effectiveness outperform existing algorithms.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-08-01","The student, Hao Wu, accepted the attached license on 2017-07-10 at 12:18.","The student, Hao Wu, submitted this Dissertation for approval on 2017-07-10 at 12:40.","This Dissertation was approved for publication on 2017-07-10 at 17:31.","DSpace SAF Submission Ingestion Package generated from Vireo submission #11365 on 2017-09-29 at 11:15:00","Made available in DSpace on 2017-09-29T16:39:23Z (GMT). No. of bitstreams: 5 WU-DISSERTATION-2017.pdf: 1628164 bytes, checksum: 3560b43774c77f1933af8a25bdf134e0 (MD5) phd_thesis_src.zip: 17255343 bytes, checksum: fa97ce904e111eba6058d2d8a6e28413 (MD5) LICENSE.txt: 4203 bytes, checksum: 2a1e13ae68aeb9847ee1b3f4f0eb4f5f (MD5) PROQUEST_LICENSE.txt: 4549 bytes, checksum: bdb351d255c1e06d7dc3f73c5712890a (MD5) RightsLink Printable License.pdf: 83836 bytes, checksum: ee9f81a055846739b6b715ab3a67cfa7 (MD5) Previous issue date: 2017-07-10","Embargo set by: Colleen Fallaw for item 103411 Lift date: 2019-09-29T16:39:52Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Colleen Fallaw for item 103411 Lift date: 2019-09-29T17:52:45Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Open Restriction set for Item 103411 on 2018-10-05T17:54:33Z with date null by fschaef2@illinois.edu.","Open Restriction set for Item 103411 on 2018-10-05T17:54:37Z with date null by fschaef2@illinois.edu.","Open Restriction set for Item 103411 on 2018-10-05T17:54:46Z with date null by fschaef2@illinois.edu.","Open Restriction set for Item 103411 on 2018-10-05T17:54:55Z with date null by fschaef2@illinois.edu.","Open"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/98264"],"dc:language":["en"],"dc:rights":["Copyright 2017 Hao Wu"],"dc:subject":["Large-flow detection","Damage metric","Memory and computation efficiency"],"dc:title":["Site reliability against anomalous behaviors"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:35Z"}