Cybermetrics: User Identification through Network Flow Analysis

  • Nikolay Melnikov
  • Jürgen Schönwälder
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 6155)


Recent studies on user identification focused on behavioral aspects of biometric patterns, such as keystroke dynamics or activity cycles in on-line games. The aim of our work is to identify users through the detection and analysis of characteristic network flow patterns. The transformation of concepts from the biometric domain into the network domain leads to the concept of a cybermetric pattern — a pattern that identifies a user based on her characteristic Internet activity.


Cybermetrics User Identification Network Flow Analysis 


  1. 1.
    Holmes, J.P., Wright, L.J., Maxwell, R.L.: A performance evaluation of biometric identification devices. Technical report, Sandia National Laboratories, Albuquerque, NM (1991)Google Scholar
  2. 2.
    Ashbourn, J.: Biometrics: advanced identity verification. Springer, London (2000)CrossRefGoogle Scholar
  3. 3.
    Chen, K.-T., Hong, L.-W.: User identification based on game-play activity patterns. In: Proc. of the 6th ACM SIGCOMM Workshop on Network and System Support for Games (NetGames 2007), pp. 7–12. ACM, New York (2007)CrossRefGoogle Scholar
  4. 4.
    Bergadano, F., Gunetti, D., Picardi, C.: User authentication through keystroke dynamics. ACM Transactions Information System Security 5(4), 367–397 (2002)CrossRefGoogle Scholar
  5. 5.
    Ahmed, A.A.E., Traore, I.: A new biometric technology based on mouse dynamics. IEEE Transactions on Dependable and Secure Computing 4(3), 165–179 (2007)CrossRefGoogle Scholar
  6. 6.
    Perényi, M., Dang, T.D., Gefferth, A., Molnár, S.: Identification and analysis of peer-to-peer traffic. JCM 1(7), 36–46 (2006)CrossRefGoogle Scholar
  7. 7.
    Lakhina, A., Crovella, M., Diot, C.: Mining anomalies using traffic feature distributions. SIGCOMM Computer Communication Review 35(4), 217–228 (2005)CrossRefGoogle Scholar
  8. 8.
    Stoecklin, M.P., Boudec, J.-Y.L., Kind, A.: A two-layered anomaly detection technique based on multi-modal flow behavior models. In: Claypool, M., Uhlig, S. (eds.) PAM 2008. LNCS, vol. 4979, pp. 212–221. Springer, Heidelberg (2008)CrossRefGoogle Scholar

Copyright information

© IFIP International Federation for Information Processing 2010

Authors and Affiliations

  • Nikolay Melnikov
    • 1
  • Jürgen Schönwälder
    • 1
  1. 1.Computer ScienceJacobs University BremenGermany

Personalised recommendations