<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>ORCID:</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Honeypots Network Traffic Parameters Modelling</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Roman V. Maximov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sergey P. Sokolovsky</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexander P. Telenga</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Krasnodar Higher Military School named after the general of the Army S.M.Shtemenko</institution>
          ,
          <addr-line>4 Krasina ul., Krasnodar, 350963</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>One of the relevant and practically significant applications of fractal traffic analysis is modeling of network interaction processes of distributed information systems. The obtained model allows to solve such important information security problem as reproduction of false and (or) hiding of true individual information technologies and (or) structural and functional characteristics of information system or its segments. Three situations of information system functioning are considered, the parameters of network traffic that necessary for the development of the model are highlighted. The Hurst index for the time series of network traffic parameters is calculated, and the coefficients of the van der Pol nonlinear oscillator equation are selected on its basis.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Information protection</kwd>
        <kwd>false network information objects</kwd>
        <kwd>Hurst index</kwd>
        <kwd>de-masking features</kwd>
        <kwd>Van der Pol nonlinear oscillator</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The presence of fractal properties of network traffic was discovered several decades ago, when it
was found that it has the property of self-similarity, that is, it looks qualitatively the same at sufficiently
large scales of the time axis and exhibits a long-term dependence [
        <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4 ref5 ref6 ref7 ref8">1, 2, 3, 4, 5, 6, 7, 8</xref>
        ]. In particular,
unlike processes that do not have fractal properties, there is no rapid "smoothing" of the process when
averaged over the time scale - it retains a tendency to spikes.
      </p>
      <p>Prior to that, the dominant traffic models based on Markov processes had a short-term dependence.
They were borrowed from telephone networks and, as applied to computer networks, led to an
underestimation of the load. The discovery of the self-similarity of traffic had a significant impact on
the subsequent development of client-server information systems and allowed us to rethink the
probabilistic and temporal characteristics of such systems.</p>
      <p>One of the relevant and practically significant applications of fractal traffic analysis is modeling of
network interaction processes of distributed information systems. The obtained model allows not only
to predict the system behavior in various critical situations, but also to solve such important information
security problem as reproduction of false and (or) hiding of true individual information technologies
and (or) structural and functional characteristics of information system or its segments, providing
imposition of a false idea about true information technologies and (or) structural and functional
characteristics of information system to an adversary.</p>
      <p>This problem is most commonly solved by using false network information objects (honeypots) [9],
which are designed to distract the adversary from the protected system and collect information about
the techniques and tactics used for the attack [10].</p>
      <p>The homogeneous structure of modern IP networks gives an attacker an advantage in using the
computing resource to carry out computer attacks. This is due to the fact that the homogeneity of
network configurations, their hardware and software, allows adversaries to easily and with little
computational cost to conduct a large-scale attack on dozens, hundreds or thousands of nodes after
successfully conducting a small-scale attack on just one of the nodes of this homogeneous IP-network.
In turn, security services must timely detect and eliminate all potential vulnerabilities, as well as
neutralize or reduce the effectiveness of network reconnaissance and implementation of computer
attacks. Continuity in time when using traditional methods and means of protection of IP-networks
allows the attacker with sufficient ease to calculate the next step of the security system or technological
cycle implemented in the IP-network. This technique is called cyber maneuvering [11, 12, 13, 14].</p>
      <p>The problem of applying cyber maneuvering techniques is the presence of so-called critical
connections in the traffic of the information system, which, for the purpose of data transmission
continuity, cannot change their identifiers at one time.</p>
      <p>Thus, to achieve the goal of cyber maneuvering and uncompromising operation of protection
technologies, false network information objects must generate false (masking) traffic based on the
characteristics of real traffic of the information system, which will make noise in the useful network
activity and focus the attention of the adversary.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Analysis of input data for the model</title>
      <p>There are several approaches to describing information system network traffic: as flows and as a
sequence of packets ("raw" traffic).</p>
      <p>Flows contain header information about network connections between two end devices, such as
servers or workstations. Each flow is a collection of transmitted network packets that share some
properties. Generally, all transmitted network packets with the same source IP address, source port,
destination IP address, destination port and transport protocol within a time window are combined into
a single flow [15, 16, 17].</p>
      <p>"Raw" traffic typically is a sequence of packets, each containing packet sending time, source IP
address, source port, destination IP address, destination port, protocol, packet size, set flags, and a data
field in which the payload is written [18, 19, 20].</p>
      <p>Based on the above, we can conclude that the parameters that determine the network interaction
between the two nodes of the data network of a distributed information system are source IP address,
source port, destination IP address, destination port, protocol, packet size, duration of the connection.</p>
      <p>Let's take as a reference the network traffic dump recorded from 00:00:00 on 15 March 2021 to
23:59:59 on 21 March 2021. The traffic parameters in the sample under consideration are: date of first
session detection, connection duration, protocol, source IP address, source port, destination IP address,
destination port, number of packets in session, number of bytes transmitted per session. An example of
the entries is shown in Table 1 (some of the columns are hidden), 324533 records in total.</p>
      <p>192.168.220.16
192.168.220.15
2021-03-21
23:59:53.709
2021-03-21
23:59:58.299
2021-03-21
23:59:58.298
0.002
TCP
TCP</p>
      <p>192.168.100.5
192.168.100.5
445</p>
      <p>192.168.220.6
192.168.220.6
56281
56281
445
Let us examine which ports were used by the different IP addresses.</p>
      <p>The graph for source addresses is shown in Figure 1, and for destination addresses in Figure 2.</p>
      <p>In network communication over the TCP transport protocol, clients initiate a connection to servers
using the triple handshake algorithm [21], which uses the notion of a socket - an address that includes
a port identifier, i.e. the concatenation of an IP address and a TCP port:</p>
      <p>1. Sender opens a port to initiate communication. Since administrator privileges are required to
access ports below 1000, a number between 10000 and 65535 is usually chosen at random.</p>
      <p>2. Sender sends a packet with the SYN flag set to 1 to the recipient. In addition to the SYN flag,
the packet header specifies the sender IP, source port, destination IP and destination port. The sender
waits for a response from the receiver on the port opened in step 1.
3. If the recipient has a service that uses the port number specified as the destination port, it sends
a packet with SYN, ACK flags set to 1 to the source port. Otherwise, it sends a packet with the RST
flag.</p>
      <p>In Figures 1 and 2 it's easy to see that the IP addresses that are not accessing ports numbered above
10000 are servers that are serving user requests (the large number of reply sessions from these IP
addresses on ports above 10000 shows this). This is a de-masking feature that can narrow down the
attack vector of an adversary. The goal of a honeypot is to supplement network activity and mask
critical network nodes.</p>
      <p>Consider now the duration of the sessions, the number of packets and the amount of data transmitted
within each session (Figures 3, 4 and 5).</p>
    </sec>
    <sec id="sec-3">
      <title>3. Model of information system functioning</title>
      <p>Let us consider three strategies of information system functioning:
1. Normal mode – the system operates in normal mode, the intensity of traffic does not change.
2. Day/night mode – traffic intensity changes depending on time of day.</p>
      <p>3. Critical connections – part of the system degrades due to cyber-attack, traffic of critical
connections prevails.</p>
      <p>For each of the presented strategies, honeypot must generate its own variant of network traffic to
ensure uncompromised functioning of the defenses.</p>
      <p>Let us generate an information system model for the first situation.</p>
      <p>First we calculate the Hurst index [22] for the time series of source ports for all traffic dump flows
using Rescaled range (R/S) analysis [23] (Figure 6).
nonlinear oscillator equation [24], which has the form</p>
      <p>After that, we use calculated Hurst index and approximate given time series with the van der Pol
d 2 x dx
d 2t − a(1 − b dt ) + x =0 .</p>
      <p>Choosing the coefficients for the practically important case ( a &gt; 0,b &gt; 0 ) and solving differential
equations with numerical methods, for example, Runge-Kutta of order 4 and 5, we obtain that the closest
calculated value of the Hurst index HS = 0, 63184 to the value of the Hurst index H = 0, 63127 of
the studied time series of source ports is obtained at a = 19 ; b = 20 .</p>
      <p>Thus, the processing of the Van der Pol generator model series with the presented coefficients
resulted in a dependence that can be considered as a fairly accurate approximation of the empirical
series of R/S dependence for a sequence of flows with different source ports, i.e. its mathematical
model:</p>
      <p>Van der Pol generator model with the closest value of the Hurst index HS = 0, 72483 to the value</p>
      <p>Van der Pol generator model with the closest value of the Hurst index HS = 0, 66971 to the value
of the Hurst index H = 0, 66966 has a form</p>
      <p>Date
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
15.03.2021
Using a similar methodology described above, we obtain mathematical models for the parameters
of the represented traffic.</p>
      <p>Source ports:</p>
      <sec id="sec-3-1">
        <title>Destination ports:</title>
      </sec>
      <sec id="sec-3-2">
        <title>Connection duration: Session size:</title>
        <p>15.03.2021 00:01:16.552
15.03.2021 00:01:16.551
15.03.2021 00:01:16.631
15.03.2021 00:01:16.552
15.03.2021 00:01:16.631
15.03.2021 00:01:17.432
15.03.2021 00:01:17.431
15.03.2021 00:01:17.432
15.03.2021 00:01:17.827
15.03.2021 00:01:21.703</p>
      </sec>
      <sec id="sec-3-3">
        <title>Model for the nighttime network activity as follows. Source ports: Destination ports: Connection duration:</title>
        <p>A model of information system functioning with the prevalence of critical connections is presented
below.</p>
        <p>Source ports:</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions</title>
      <p>The developed models allows to determine the probabilistic and temporal characteristics describing
the states of the client-server information system functioning process at various strategies of
establishment and maintenance of connection parameters by the interacting parties, which allows to
estimate the state of the client-server information system and to adjust the parameters of protection
systems against network reconnaissance.</p>
      <p>The novelty of the developed model consists in the application of modified algorithms of fractal
analysis to assess the characteristics of network traffic to improve the reliability, accuracy and validity
of honeypots.</p>
    </sec>
    <sec id="sec-5">
      <title>5. References</title>
      <p>[9] N. Bhagat and B. Arora, "Intrusion Detection Using Honeypots," 2018 Fifth International
Conference on Parallel, Distributed and Grid Computing (PDGC), 2018, pp. 412-417, doi:
10.1109/PDGC.2018.8745761.
[10] R. Kwon, T. Ashley, J. Castleberry, P. Mckenzie and S. N. Gupta Gourisetti, Cyber Threat
Dictionary Using MITRE ATT&amp;CK Matrix and NIST Cybersecurity Framework Mapping, 2020
Resilience Week (RWS), 2020, pp. 106-112, doi:10.1109/RWS50334.2020.9241271.
[11] S. Applegate, "The principle of maneuver in cyber operations," in In 2012 4th International</p>
      <p>Conference on Cyber Conflict (CYCON 2012), 2012
[12] Allen, Patrick D. “Cyber Maneuver and Schemes of Maneuver: Preliminary Concepts, Definitions,
and Examples.” The Cyber Defense Review, vol. 5, no. 3, 2020, pp. 79–98. JSTOR,
www.jstor.org/stable/26954874.
[13] P. Beraud, A. Cruz, S. Hassell and S. Meadows, "Using cyber maneuver to improve network
resiliency," 2011 - MILCOM 2011 Military Communications Conference, 2011, pp. 1121-1126,
doi: 10.1109/MILCOM.2011.6127449.
[14] P. Beraud, A. Cruz, S. Hassell, J. Sandoval and J. J. Wiley, "Cyber defense Network Maneuver
Commander," 44th Annual 2010 IEEE International Carnahan Conference on Security
Technology, 2010, pp. 112-120, doi: 10.1109/CCST.2010.5678724.
[15] S. Choudhary, “Usage of Netflow in Security and Monitoring of Computer Networks,” Interntional</p>
      <p>Journal of Computer Applications, vol. 68, no. 24, pp. 17–24, 2013, doi:10.5120/11727-7362.
[16] R. Hofstede, P. Celeda, B. Trammell, I. Drago, R. Sadre, A. Sperotto, and A. Pras, “Flow
Monitoring Explained : From Packet Capture to Data Analysis with NetFlow and IPFIX,” IEEE
Communications Surveys &amp; Tutorials, vol. 16, no. 4, 2014, doi: 10.1109/COMST.2014.2321898.
[17] M. Marchetti, F. Pierazzi, M. Colajanni, and A. Guido, “Analysis of high volumes of network
traffic for Advanced Persistent Threat detection,” Computer Networks, vol. 0, pp. 1–15, 2016,
doi:10.1016/j.comnet.2016.05.018
[18] B. Alothman, "Raw Network Traffic Data Preprocessing and Preparation for Automatic Analysis,"
2019 International Conference on Cyber Security and Protection of Digital Services (Cyber
Security), 2019, pp. 1-5, doi: 10.1109/CyberSecPODS.2019.8885333.
[19] J. J. Davis and A. J. Clark, “Data preprocessing for anomaly based network intrusion detection: A
review,” Comput. Secur., vol. 30, no. 6-7, pp. 353–375, 2011, doi:10.1016/j.cose.2011.05.008
[20] Michael J. De Lucia, Paul E. Maxwell, Nathaniel D. Bastian, Ananthram Swami, Brian Jalaian,
and Nandi Leslie "Machine learning raw network traffic detection", Proc. SPIE 11746, Artificial
Intelligence and Machine Learning for Multi-Domain Operations Applications III, 117460V, 2021,
doi:10.1117/12.2586114
[21] J. Postel, “Transmission Control Protocol,” IETF RFC 793, September 1981.
[22] Н. Hurst, R. Black, Y. Simaika, Long-Term Storage: An Experimental Study, Constable, London,
1965
[23] Raimundo, M.S.; Okamoto, J., Jr. Application of Hurst Exponent (H) and the R/S Analysis in the</p>
      <p>Classification of FOREX Securities. Int. J. Model. Optim. 2018, 8, 116–124.
[24] J. He, J. Cai, Design of a New Chaotic System Based on Van Der Pol Oscillator and Its Encryption
Application, Mathematics, 2019, 7, 743. doi:10.3390/math7080743.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>P.</given-names>
            <surname>Dymora</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <article-title>Influence of Model and Traffic Pattern on Determining the SelfSimilarity in IP Networks</article-title>
          .
          <source>Applied Sciences</source>
          ,
          <volume>11</volume>
          , (
          <year>2021</year>
          ),
          <volume>190</volume>
          . doi:
          <volume>10</volume>
          .3390/app11010190.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Guerrero-Ibanez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Contreras-Castillo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Buenrostro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. B.</given-names>
            <surname>Marti</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Munoz</surname>
          </string-name>
          ,
          <article-title>A policybased multi-agent management approach for intelligent traffic-light control</article-title>
          ,
          <source>IEEE Intelligent Vehicles Symposium</source>
          , University of California, San Diego, USA,
          <year>June 2010</year>
          . doi:
          <volume>10</volume>
          .1109/IVS.
          <year>2010</year>
          .
          <volume>5548133</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bhattacharjee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Nandi</surname>
          </string-name>
          ,
          <article-title>Statistical analysis of network traffic inter-arrival, 2010</article-title>
          <source>The 12th International Conference on Advanced Communication Technology (ICACT)</source>
          ,
          <year>2010</year>
          , pp.
          <fpage>1052</fpage>
          -
          <lpage>1057</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Fang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Liu</surname>
          </string-name>
          , and
          <string-name>
            <given-names>W.</given-names>
            <surname>Gong</surname>
          </string-name>
          .
          <article-title>Double pareto lognormal distributions in complex networks</article-title>
          ,
          <source>Handbook of Optimization in Complex Networks</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>55</fpage>
          -
          <lpage>80</lpage>
          , doi:10.1007/978-1-
          <fpage>4614</fpage>
          -0754-6.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Ghosh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Jana</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Ramaswami</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Rowland</surname>
          </string-name>
          , and
          <string-name>
            <given-names>N. K.</given-names>
            <surname>Shankaranarayanan</surname>
          </string-name>
          .
          <article-title>Modeling and characterization of large-scale wi-fi traffic in public hot-spots</article-title>
          .
          <source>In INFOCOM</source>
          ,
          <year>2011</year>
          . doi:
          <volume>10</volume>
          .1109/INFCOM.
          <year>2011</year>
          .
          <volume>5935132</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>O. I.</given-names>
            <surname>Sheluhin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Smolskiy</surname>
          </string-name>
          and
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Osin</surname>
          </string-name>
          , Self-Similar Processes in Telecommunications, Wiley, London,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Voronchikhin</surname>
            <given-names>I.</given-names>
          </string-name>
          , Ivanov .,
          <string-name>
            <surname>Maximov</surname>
            <given-names>R.</given-names>
          </string-name>
          , Sokolovsky S.
          <article-title>Masking of distributed information systems structure in cyberspace</article-title>
          .
          <source>Voprosy kiberbezopasnosti</source>
          ,
          <year>2019</year>
          , No 6, pp.
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          - 3456-2019-6-
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
          . (In Russ.)
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Kuchurov</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maximov</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sherstobitov</surname>
            <given-names>R</given-names>
          </string-name>
          .
          <article-title>Model and technique for abonent address masking in cyberspace</article-title>
          .
          <source>Voprosy kiberbezopasnosti</source>
          ,
          <year>2020</year>
          , No
          <volume>6</volume>
          (
          <issue>40</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>13</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456- 2020-06-2-
          <lpage>13</lpage>
          . (In Russ.)
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>