<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>HS =</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="hindawi-id">4019749</article-id>
      <article-id pub-id-type="doi">10.3233/JIFS-169387</article-id>
      <title-group>
        <article-title>Methodology for Substantiating the Characteristics of False Network Traffic to Simulate Information Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Roman V. Maximov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sergey P. Sokolovsky</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexander P. Telenga</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Krasnodar Higher Military School named after the general of the Army S.M.Shtemenko</institution>
          ,
          <addr-line>4 Krasina ul., Krasnodar, 350963</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <volume>0</volume>
      <issue>66881</issue>
      <fpage>6</fpage>
      <lpage>7</lpage>
      <abstract>
        <p>Simulation of false information traffic to protect the structural and functional characteristics of the information system is not an easy task in view of self-similarity of its statistical properties in IP-networks not only in the current moment, but also retrospectively. We have developed a methodology to substantiate the characteristics of false network traffic to simulate information systems, allowing to solve the problem of maximum likelihood of false network traffic by pseudophase reconstruction of the dynamic system attractor, which approximates the time series of the protected object information traffic.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Information protection</kwd>
        <kwd>false network information objects</kwd>
        <kwd>Hurst index</kwd>
        <kwd>de-masking features</kwd>
        <kwd>pseudo-phase reconstruction</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Information protection measures in state information systems currently include:
• hiding the architecture and configuration of the information system;
• creation (emulation) of false information systems or their components designed to detect,
register and analyze the actions of intruders in the process of implementing threats to information
security;
• reproduction of false and (or) concealment of true individual information technologies and (or)
structural and functional characteristics of the information system or its segments, ensuring the
imposition of a false idea on the offender about the true information technologies and (or) structural
and functional characteristics of the information system.</p>
      <p>
        This is due to the fact that a sufficiently large number of computer attacks are reconnaissance in
nature in order to obtain information about the composition, structure and algorithms of the functioning,
location and ownership of information systems, as well as data stored, processed and transmitted in
such systems. Along with the threats to information security, related to the dialog interaction of the
intruder and information system (in particular – automated network scanning tools), the reconstruction
of structural and functional characteristics of information system is aimed at the threat of determining
its topology, uncompromisingly implemented by the analysis of network traffic. The result is revealing
the topology of the cyberspace distributed information system, determining the importance of its nodes
witch could be used by an intruder to implement planned APT-attacks (advanced persistent threat,
targeted cyberattack) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>The task of implementing the above information protection measures is solved by false (masking)
information traffic, which is understood as a set of false (masking) message packets formed by network
information objects in order to manage the demasking signs of information systems functioning
algorithms: the intensity of traffic between topologically localized network information objects of a
distributed information system, network interaction protocols and hierarchical levels (ranks) of its
elements.</p>
      <p>For this purpose, false network information objects (also called "deceptive" systems) are used, which
implement dialog interaction with the intruder, which leads to "depletion" of its computing resources
and compromises the processes of tampering.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Methodology description</title>
      <p>
        It is known the way to protect computer networks [
        <xref ref-type="bibr" rid="ref2 ref3 ref4">2, 3, 4</xref>
        ], which implements the technique of cyber
maneuver - periodic (time-synchronized) or uncontrolled (random) change of network settings of the
protected system (used address space and port numbers of subscribers) -, where upon detection of an
intruder the DHCP server forcibly stops leasing current IP addresses by legitimate subscribers of the
information system and sends them new network settings containing IP addresses from a different
subnet not known to the intruder in advance. This task is complicated by the presence in the information
system of critical applications and network traffic between them (so called "critical connections"),
interruption of which is undesirable or impossible. As a result of network intelligence, they will be
vulnerable to computer attacks. In order to eliminate this threat, it is not just necessary to transfer
subscribers (network information objects) in another subnetwork, but also to "load" the network
information objects of the compromised configuration with the functions of false objects. We need to
maintain false information traffic between them, which has statistical characteristics of the
compromised information system, so that the cyber maneuver will not be detected by an intruder.
      </p>
      <p>The following variants of solving the problem of false (masking) information traffic are possible.</p>
      <p>Pre-recording of information system network traffic and subsequent sending of saved packets to the
network. In this case, the time interval between packets is taken from the network traffic record.
Disadvantages of this approach, associated with the need to store large amounts of data, are obvious. In
addition, with a relatively small number of subscribers in the information system it is possible to detect
the fact of re-use (cloning) of traffic.</p>
      <p>Another, and more preferable, method is the generation of false (masking) information traffic based
on the characteristics of real traffic, which is performed by a false network information object. In order
to ensure maximum plausibility of false network traffic, its statistical properties must match the
statistical properties of the information traffic of the protection object. Otherwise the application of
such protection measures will be compromised, and the goals of simulation will not be achieved.</p>
      <p>Thus, there is a contradiction between the need to implement an effective masking exchange and the
lack of a unified way to assess the characteristics of network traffic for the false information exchange
generation in the system.</p>
      <p>
        Simulation of false information traffic for protection of information system structural and functional
characteristics is a complex task in view of self-similarity of its statistical properties in IP-networks [
        <xref ref-type="bibr" rid="ref5 ref6 ref7 ref8">5,
6, 7, 8</xref>
        ] not only in the current moment, but also retrospectively. This means that some property of the
object is preserved when scaling space and/or time. Otherwise, they say that there is a repeatability of
statistical characteristics of natural time series with the change of scale.
      </p>
      <p>
        It is known [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13 ref14 ref9">9, 10, 11, 12, 13, 14</xref>
        ] that the processes with self-similarity properties are characterized
by the presence of aftereffects due to the factors that cause complex dependencies. The resulting traffic
(process in general case) becomes "pulsating": large bursts of intensity are possible at relatively low
average rate of arrival of message packets in an information system. Statistical characteristics of such
a process are the de-masking features of a particular system. [15, 16, 17, 18].
      </p>
      <p>Today, global networking is growing exponentially, with traffic statistics that mathematically
exhibit fractal characteristics: self-similarity and long-range dependence. With these properties, data
traffic shows high peak-to-average bandwidth ratios and causes data networks inefficient. These
problems make it difficult to predict, quantify, and control data traffic, in contrast to the traditional
Poisson-distributed traffic in telephone networks [19, 20].</p>
      <p>A commonly used index of self-similarity of a process is the Hurst index H , initially introduced
in [21], depending on its values the following conclusions about the processes under study are drawn:
• at 0 ≤ H ≤ 0,5 is a random process, it has no self-similarity;
• at H &gt; 0, 5 the process has a long memory and is self-similar [22].</p>
      <p>The Hearst index calculations use the algorithm for analyzing the adjusted modified range proposed
in [23], [24], which consists in the following.</p>
      <sec id="sec-2-1">
        <title>Let the time series be given</title>
        <p>Z</p>
        <p>={zi },i =1, 2,..., n .
in which its initial segments are sequentially allocated</p>
        <p>Zτ = z1, z2 ,..., zτ , where τ = 3, 4,..., n ,
for each of which the current average is calculated</p>
        <p>1 τ
zτ = ∑ zi (3)</p>
        <p>τ i=1</p>
        <p>Next, for each fixed zτ ,τ = 3, 4,..., n , calculate the accumulated deviation for each of the segments
of length t :</p>
        <p>t
X (t,τ ) =∑ (zi − zτ ) , where t = 1,τ</p>
        <p>i=1
The main characteristic of a sample of a random process is the normalized range R/S, where
R(τ ) =max X (t,τ ) − min X (t,τ )</p>
        <p>1≤t≤τ 1≤t≤τ
maximum amplitude range of the random process, S is standard deviation of the process
S
=S (τ ) =
1 τ</p>
        <p>∑ (z j − zτ )2 ,
τ j=1
t - discrete time with integer values; τ - duration of the time interval in question.</p>
        <p>The normalized R/S spread is described by the empirical relation R / S = (τ / 2)H , where H is the</p>
      </sec>
      <sec id="sec-2-2">
        <title>Hurst index.</title>
        <p>We obtain the Cartesian coordinates of the trajectory points ( xτ , yτ ) by logarithmization of both
parts of this equality (6), whose ordinates and abscissas are, respectively:</p>
        <p>log(R(τ ) / S (τ ))
yτ =H (τ ) = , xτ =τ.</p>
        <p>log(τ / 2)</p>
        <p>The R/S-trajectory required for the fractal analysis of the series is represented in Cartesian
logarithmic coordinates by a sequence of points, the abscissas and ordinates of which are as follows
xτ = log(τ / 2) , yτ = log(R(τ ) / S (τ )) .</p>
        <p>Let a sample (dump) of information system traffic X t for some set of time moments t ≤ T be
obtained at time T . Then the model of prediction of characteristics of information traffic defines a set
where vector aT represents the model coefficients derived from the results of traffic dumping up to
and including moment T , and matrix F represents the set of approximating functions.</p>
        <p>In most cases, it is necessary to study only the attractor, a compact subset of the phase space to which
the evolution trajectories of all points of the system located near this subset are asymptotically
"attracted", in order to analyze the behavior of the dynamical system (8). Its dimensionality determines
the amount of information required to specify the coordinates of a point belonging to the attractor within
the specified accuracy.</p>
        <p>The fractal dimension D can be expressed through the Hearst index H by the ratio</p>
        <p>D = 2 − H . (9)</p>
        <p>The attractor is related to the fractal dimension through the correlation integral C(r) , which is
estimated directly for a sequence of points (shows the relative number of pairs of points at a distance
not greater than r ):</p>
        <p>C(r)</p>
        <p>1 m m
=lim∑ ∑θ (r − ρ (xi , x j )) ,
m→∞ m(m − 1) i=1 j=1
(10)
where
(1)
(2)
(4)
(5)
(6)
(7)
1,α ≥ 0,
θ (α ) =  (11)</p>
        <p>0,α &lt; 0
(Haviside function), ρ is the distance between a pair of points in n -dimensional phase space, and
m is the number of points xi on the attractor.</p>
        <p>Tackens in [25] showed that for almost every smooth dynamical system it is possible to calculate
the correlation integral and the fractal dimension by measurements of only one of the phase coordinates
of this system.</p>
        <p>The method for synthesizing a mathematical model of a process described in [26] is based on the
application of the so-called pseudophase reconstruction.</p>
        <p>A pseudophase reconstruction [27] is a mapping that maps the x(t) point of a time series to the
[x(t), x(t +τ ),..., x(t + (m −1) ⋅τ )]∈ Rm point, where t is the discrete time (t = ((m −1)τ + 1), N )) , τ is
the time delay (in time discretes), and m is the dimension of the embedding space. Thus, it is possible
to reconstruct the original attractor in the point space with delay [x(t), x(t +τ ),..., x(t + (m −1) ⋅τ )] for
an initial set of measurements of the phase coordinate x(1), x(2),..., x(N ), , where N is the number of
measurements, so that it preserves the essential topological properties and dynamics of the original
attractor. The attractor dimension m is determined by the formula m ≥ 2[d ] + 1 , where d is the fractal
dimension of the attractor.</p>
        <p>Consequently, in order to synthesize a mathematical model of the network traffic of the system under
study, it is necessary to calculate the Hurst exponent H for one of the parameters of the network traffic
dump and then, using the known mathematical models of attractors, select their coefficients so that the
Hurst exponent H S of the synthesized time series coincides with H with an accuracy of some ε .</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Example of methodology application</title>
      <p>Let us consider a traffic dump of 211972 packets from an Internet subscriber point (Table 1). We
want to synthesize a mathematical model of this dump to predict, quantify, and control destination ports
of data traffic.</p>
      <p>Protocol</p>
      <p>TCP
TCP
TCP
HTTP
TCP
TCP
TCP
TCP
TCP
TCP
TCP
TCP
TCP
TCP
TCP
TCP
TCP</p>
      <p>Length
1494
66
66
1494
1494
1494
1494
1494
1494
1494
1494</p>
      <p>66
1494
1494
1494
66
66</p>
      <p>66
1494
66</p>
      <p>We filter out packages by destination port and present them as a time series (Figure 1). Then we
calculate R/S spread and Hurts index using the algorithm above.</p>
      <p>The results of calculating the time dependence of the normalized R/S spread in double logarithmic
scale and its linear approximation for packets filtered by destination port are shown in Figure 2.</p>
      <p>Hearst index for the studied time series H = 0, 67199 , fractal dimension D =2– H =1,32801 .
Let us approximate the time series under study, for example, by the van der Pol nonlinear oscillator
d 2 x dx
equation [28], which has the form 2 − a(1 − b ) + x =0 .</p>
      <p>d t dt</p>
      <p>Choosing the coefficients for the practically important case ( a &gt; 0,b &gt; 0 ) and solving differential
equations with numerical methods, for example, Runge-Kutta of order 4 and 5, we obtain that the closest
calculated value of the Hurst index HS = 0, 67199 to the value of the Hurst index H = 0, 67199 of the
studied time series of packages filtered by destination ports is obtained at a = 8,514 ; b = 10 .</p>
      <p>Thus, the processing of the Van der Pol generator model series with the presented coefficients
resulted in a dependence that can be considered as a fairly accurate approximation of the empirical
series of R/S dependence for a sequence of packets with different destination ports, i.e. its mathematical
model:</p>
      <p>Now let’s examine packages filtered by source port and present them as a time series (Figure 1).
Then we calculate R/S spread and Hurts index.</p>
      <p>The results of calculating the time dependence of the normalized R/S spread in double logarithmic
scale and its linear approximation for packets filtered by destination port are shown in Figure 6.</p>
      <p>Hearst index for the studied time series H = 0, 66513 , fractal dimension D =2– H =1,33487 .</p>
      <p>Let us approximate the time series of source port packages by the Rössler system [29], which has
the form</p>
      <p>Iterate the confidents a , b , and c and solving the system of differential equations with numerical
methods using GNU Octave lsode solver we obtain that the closest calculated value of the Hurst index
x =− y − z
y = x + ay
z =b − cz + xz
filtered by source ports is obtained at a = 0,2 , b = 0, 2 , c = 5, 2 .</p>
      <p>Thus, the processing of the Rössler system model series with the presented coefficients resulted in
a dependence that can be considered as a fairly accurate approximation of the empirical series of R/S
dependence for a sequence of packets with different source ports, i.e. its mathematical model:
x =− y − z</p>
      <p>,
HS = 0, 66881, D
=2– HS</p>
      <p>The resulting mathematical models can be used to adjust honeypot parameters, allowing the
synthesis of false network traffic to different ports that is statistically similar to the reference traffic.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions</title>
      <p>Thus, the paper substantiates the possibility of analyzing the information system de-masking
features and generation of false network traffic, statistically similar to the traffic of the protected
information system, to reduce the effectiveness of network reconnaissance.</p>
      <p>The novelty of the developed methodology consists in the application of modified algorithms of
fractal analysis to assess the characteristics of network traffic and synthesis of its mathematical model
to improve the reliability of false network information objects.</p>
      <p>The implementation of the proposed scientific solutions in the information system structure will
reduce the availability of its elements and management processes, which will ensure the weakening of
the influence or neutralization of network reconnaissance, as well as deprive the attacker the necessary
information about the structure of a distributed information system.</p>
    </sec>
    <sec id="sec-5">
      <title>5. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>R.</given-names>
            <surname>Kwon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Ashley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Castleberry</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Mckenzie</surname>
          </string-name>
          and
          <string-name>
            <given-names>S. N.</given-names>
            <surname>Gupta</surname>
          </string-name>
          <string-name>
            <surname>Gourisetti</surname>
          </string-name>
          ,
          <article-title>Cyber Threat Dictionary Using MITRE ATT&amp;CK Matrix and</article-title>
          NIST Cybersecurity Framework Mapping,
          <source>2020 Resilience Week (RWS)</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>106</fpage>
          -
          <lpage>112</lpage>
          , doi:10.1109/RWS50334.
          <year>2020</year>
          .
          <volume>9241271</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>R.</given-names>
            <surname>Maksimov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Sokolovsky</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Voronchikhin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gritschin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bodiakin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ignatenko</surname>
          </string-name>
          ,
          <year>2020</year>
          . Patent No.
          <source>RU 2726900</source>
          ,
          <string-name>
            <surname>Filed</surname>
            <given-names>November 9th</given-names>
          </string-name>
          ,
          <year>2019</year>
          ,
          <string-name>
            <given-names>Issued</given-names>
            <surname>July</surname>
          </string-name>
          16th,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Voronchikhin</surname>
            <given-names>I.</given-names>
          </string-name>
          , Ivanov .,
          <string-name>
            <surname>Maximov</surname>
            <given-names>R.</given-names>
          </string-name>
          , Sokolovsky S.
          <article-title>Masking of distributed information systems structure in cyberspace</article-title>
          .
          <source>Voprosy kiberbezopasnosti</source>
          ,
          <year>2019</year>
          , No 6, pp.
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          - 3456-2019-6-
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
          . (In Russ.)
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Kuchurov</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maximov</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sherstobitov</surname>
            <given-names>R</given-names>
          </string-name>
          .
          <article-title>Model and technique for abonent address masking in cyberspace</article-title>
          .
          <source>Voprosy kiberbezopasnosti</source>
          ,
          <year>2020</year>
          , No
          <volume>6</volume>
          (
          <issue>40</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>13</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456- 2020-06-2-
          <lpage>13</lpage>
          . (In Russ.)
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>W.</given-names>
            <surname>Leland</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Taqqu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Willinger</surname>
          </string-name>
          , D. Wilson,
          <article-title>On the self-similar nature of Ethernet traffic</article-title>
          ,
          <source>IEEE/ACM Transactions on Networking</source>
          <volume>2</volume>
          (
          <year>1994</year>
          )
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
          . doi:
          <volume>10</volume>
          .1109/90.282603
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>K.</given-names>
            <surname>Park</surname>
          </string-name>
          , W. Willinger,
          <article-title>Self-similar network traffic: an overview</article-title>
          , in K. Pack, W. Willinger (Ed.)
          <string-name>
            <surname>Self-Similar Network</surname>
            Traffic and
            <given-names>Performance</given-names>
          </string-name>
          <string-name>
            <surname>Evaluation</surname>
          </string-name>
          , John Wiley &amp; Sons, New York,
          <year>2000</year>
          , pp.
          <fpage>1</fpage>
          . doi:
          <volume>10</volume>
          .1002/047120644X
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>K.</given-names>
            <surname>Park</surname>
          </string-name>
          , G. Kim,
          <string-name>
            <surname>M.E. Crovella,</surname>
          </string-name>
          <article-title>The protocol stack and its modulating effect on self-similar traffic</article-title>
          , in K. Pack, W. Willinger (Ed.)
          <string-name>
            <surname>Self-Similar Network</surname>
            Traffic and
            <given-names>Performance</given-names>
          </string-name>
          <string-name>
            <surname>Evaluation</surname>
          </string-name>
          , John Wiley &amp; Sons, New York,
          <year>2000</year>
          , pp.
          <fpage>349</fpage>
          . doi:
          <volume>10</volume>
          .1002/047120644X
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Park</surname>
          </string-name>
          , G. Kim,
          <string-name>
            <given-names>M.E.</given-names>
            <surname>Crovella</surname>
          </string-name>
          ,
          <article-title>On the relationship between file sizes, transport protocols, and self-similar network traffic</article-title>
          ,
          <source>in Proceedings of the Fourth International Conference on Network Protocols (ICNP'96)</source>
          , Columbus,
          <string-name>
            <surname>OH</surname>
          </string-name>
          ,
          <year>1996</year>
          , pp.
          <fpage>171</fpage>
          -
          <lpage>180</lpage>
          . doi:
          <volume>10</volume>
          .1109/ICNP.
          <year>1996</year>
          .564935
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>P.</given-names>
            <surname>Dymora</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <article-title>Influence of Model and Traffic Pattern on Determining the SelfSimilarity in IP Networks</article-title>
          .
          <source>Applied Sciences</source>
          ,
          <volume>11</volume>
          , (
          <year>2021</year>
          ),
          <volume>190</volume>
          . doi:
          <volume>10</volume>
          .3390/app11010190.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Guerrero-Ibanez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Contreras-Castillo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Buenrostro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. B.</given-names>
            <surname>Marti</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Munoz</surname>
          </string-name>
          ,
          <article-title>A policybased multi-agent management approach for intelligent traffic-light control</article-title>
          ,
          <source>IEEE Intelligent Vehicles Symposium</source>
          , University of California, San Diego, USA,
          <year>June 2010</year>
          . doi:
          <volume>10</volume>
          .1109/IVS.
          <year>2010</year>
          .
          <volume>5548133</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bhattacharjee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Nandi</surname>
          </string-name>
          ,
          <article-title>Statistical analysis of network traffic inter-arrival, 2010</article-title>
          <source>The 12th International Conference on Advanced Communication Technology (ICACT)</source>
          ,
          <year>2010</year>
          , pp.
          <fpage>1052</fpage>
          -
          <lpage>1057</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Fang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Liu</surname>
          </string-name>
          , and
          <string-name>
            <given-names>W.</given-names>
            <surname>Gong</surname>
          </string-name>
          .
          <article-title>Double pareto lognormal distributions in complex networks</article-title>
          ,
          <source>Handbook of Optimization in Complex Networks</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>55</fpage>
          -
          <lpage>80</lpage>
          , doi:10.1007/978-1-
          <fpage>4614</fpage>
          -0754-6.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>A.</given-names>
            <surname>Ghosh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Jana</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Ramaswami</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Rowland</surname>
          </string-name>
          , and
          <string-name>
            <given-names>N. K.</given-names>
            <surname>Shankaranarayanan</surname>
          </string-name>
          .
          <article-title>Modeling and characterization of large-scale wi-fi traffic in public hot-spots</article-title>
          .
          <source>In INFOCOM</source>
          ,
          <year>2011</year>
          . doi:
          <volume>10</volume>
          .1109/INFCOM.
          <year>2011</year>
          .
          <volume>5935132</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>O. I.</given-names>
            <surname>Sheluhin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Smolskiy</surname>
          </string-name>
          and
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Osin</surname>
          </string-name>
          , Self-Similar Processes in Telecommunications, Wiley, London,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>