{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T09:01:40Z","timestamp":1762506100085,"version":"3.41.0"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2013,5,1]],"date-time":"2013-05-01T00:00:00Z","timestamp":1367366400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000143","name":"Division of Computing and Communication Foundations","doi-asserted-by":"publisher","award":["CCF-091694"],"award-info":[{"award-number":["CCF-091694"]}],"id":[{"id":"10.13039\/100000143","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Model. Comput. Simul."],"published-print":{"date-parts":[[2013,5]]},"abstract":"<jats:p>The Internet has been evolving into a more heterogeneous internetwork with diverse new applications imposing more stringent bandwidth and QoS requirements. Already new applications such as YouTube, Hulu, and Netflix are consuming a large fraction of the total bandwidth. We argue that, in order to engineer future internets such that they can adequately cater to their increasingly diverse and complex set of applications while using resources efficiently, it is critical to be able to characterize the load that emerging and future applications place on the underlying network. In this article, we investigate entropy as a metric for characterizing per-flow network traffic complexity. While previous work has analyzed aggregated network traffic, we focus on studying isolated traffic flows. Per-application flow characterization caters to the need of network control functions such as traffic scheduling and admission control at the edges of the network. Such control functions necessitate differentiating network traffic on a per-application basis. The \u201centropy fingerprints\u201d that we get from our entropy estimator summarize many characteristics of each application's network traffic. Not only can we compare applications on the basis of peak entropy, but we can also categorize them based on a number of other properties of the fingerprints.<\/jats:p>","DOI":"10.1145\/2457459.2457463","type":"journal-article","created":{"date-parts":[[2013,5,14]],"date-time":"2013-05-14T12:15:20Z","timestamp":1368533720000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Characterizing per-application network traffic using entropy"],"prefix":"10.1145","volume":"23","author":[{"given":"Vladislav","family":"Petkov","sequence":"first","affiliation":[{"name":"University of California Santa Cruz, Santa Cruz, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ram","family":"Rajagopal","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Katia","family":"Obraczka","sequence":"additional","affiliation":[{"name":"University of California Santa Cruz, Santa Cruz, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,5,10]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Apple. 2010a. iChat in OS X Leopard. http:\/\/www.apple.com\/asia\/macosx\/leopard\/features\/ichat.html.  Apple. 2010a. iChat in OS X Leopard. http:\/\/www.apple.com\/asia\/macosx\/leopard\/features\/ichat.html."},{"key":"e_1_2_1_2_1","unstructured":"Apple. 2010b. iChat Wikipedia entry. http:\/\/en.wikipedia.org\/wiki\/Ichat.  Apple. 2010b. iChat Wikipedia entry. http:\/\/en.wikipedia.org\/wiki\/Ichat."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1137\/1104033"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/26.380206"},{"key":"e_1_2_1_5_1","first-page":"164","article-title":"National laboratory network research. tcpdump: The protocol packet capture and dumper program. http:\/\/www.tcpdump.org","volume":"2003","author":"Berkeley L.","year":"2001","unstructured":"Berkeley , L. 2001 . National laboratory network research. tcpdump: The protocol packet capture and dumper program. http:\/\/www.tcpdump.org . In The Protocol Packet Capture and Dumper Program , 2003. 164 . Berkeley, L. 2001. National laboratory network research. tcpdump: The protocol packet capture and dumper program. http:\/\/www.tcpdump.org. In The Protocol Packet Capture and Dumper Program, 2003. 164.","journal-title":"The Protocol Packet Capture and Dumper Program"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2008.2008927"},{"key":"e_1_2_1_7_1","unstructured":"Contributors. 2010. YouTube Wikipedia entry. http:\/\/en.wikipedia.org\/w\/index.php&quest;title=Youtube&oldid= 380031496.  Contributors. 2010. YouTube Wikipedia entry. http:\/\/en.wikipedia.org\/w\/index.php&quest;title=Youtube&oldid= 380031496."},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Cover T. M. and Thomas J. A. 1991. Elements of Information Theory. Wiley-Interscience New York.   Cover T. M. and Thomas J. A. 1991. Elements of Information Theory. Wiley-Interscience New York.","DOI":"10.1002\/0471200611"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.650143"},{"volume-title":"Proceedings of the DARPA Information Survivability Conference and Exposition. 303--314","author":"Feinstein L.","key":"e_1_2_1_10_1","unstructured":"Feinstein , L. , Schnackenberg , D. , Balupari , R. , and Kindred , D . 2003. Statistical approaches to ddos attack detection and response . In Proceedings of the DARPA Information Survivability Conference and Exposition. 303--314 . Feinstein, L., Schnackenberg, D., Balupari, R., and Kindred, D. 2003. Statistical approaches to ddos attack detection and response. In Proceedings of the DARPA Information Survivability Conference and Exposition. 303--314."},{"volume-title":"Proceedings of the IEEE International Symposium on Information Theory. 645--649","author":"Gao Y.","key":"e_1_2_1_11_1","unstructured":"Gao , Y. , Kontoyiannis , I. , and Bienenstock , E . 2006. From the entropy to the statistical structure of spike trains . In Proceedings of the IEEE International Symposium on Information Theory. 645--649 . Gao, Y., Kontoyiannis, I., and Bienenstock, E. 2006. From the entropy to the statistical structure of spike trains. In Proceedings of the IEEE International Symposium on Information Theory. 645--649."},{"key":"e_1_2_1_12_1","unstructured":"Google. 2010. GoogleTalk developer info. http:\/\/code.google.com\/apis\/talk\/open_communications.html.  Google. 2010. GoogleTalk developer info. http:\/\/code.google.com\/apis\/talk\/open_communications.html."},{"key":"e_1_2_1_13_1","unstructured":"Hulu. Hulu media faq. http:\/\/www.hulu.com\/about\/media_faq.  Hulu. Hulu media faq. http:\/\/www.hulu.com\/about\/media_faq."},{"key":"e_1_2_1_14_1","unstructured":"Hunt N. 2008. Netflix encoding for streaming. http:\/\/blog.netflix.com\/2008\/11\/encoding-for-streaming.html.  Hunt N. 2008. Netflix encoding for streaming. http:\/\/blog.netflix.com\/2008\/11\/encoding-for-streaming.html."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/956993.957004"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080091.1080118"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1140277.1140295"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/166237.166255"},{"key":"e_1_2_1_19_1","unstructured":"Norris R. 1998. Markov Chains (Cambridge Series in Statistics and Probabilistic Mathematics). Cambridge University Press.  Norris R. 1998. Markov Chains (Cambridge Series in Statistics and Probabilistic Mathematics). Cambridge University Press."},{"volume-title":"Proceedings of the IEEE International Conference on Network Protocols. 171--180","author":"Park K.","key":"e_1_2_1_20_1","unstructured":"Park , K. , Kim , G. , and Crovella , M . 1996. On the relationship between file sizes, transport protocols, and self-similar network traffic . In Proceedings of the IEEE International Conference on Network Protocols. 171--180 . Park, K., Kim, G., and Crovella, M. 1996. On the relationship between file sizes, transport protocols, and self-similar network traffic. In Proceedings of the IEEE International Conference on Network Protocols. 171--180."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.392383"},{"volume-title":"Proceedings of the 2nd International Conference on Performance Evaluation Methodologies and Tools (ValueTools'07)","author":"Per\u00e9nyi M.","key":"e_1_2_1_22_1","unstructured":"Per\u00e9nyi , M. and Moln\u00e1r , S . 2007. Enhanced Skype traffic identification . In Proceedings of the 2nd International Conference on Performance Evaluation Methodologies and Tools (ValueTools'07) . ICST (Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering), Brussels, Belgium, 1--9. Per\u00e9nyi, M. and Moln\u00e1r, S. 2007. Enhanced Skype traffic identification. In Proceedings of the 2nd International Conference on Performance Evaluation Methodologies and Tools (ValueTools'07). ICST (Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering), Brussels, Belgium, 1--9."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1152\/ajpheart.2000.278.6.H2039"},{"volume-title":"Proceedings of IEEE INFOCOM. 1107--1115","author":"Riihijarvi J.","key":"e_1_2_1_24_1","unstructured":"Riihijarvi , J. , Wellens , M. , and Mahonen , P . 2009. Measuring complexity and predictability in networks with multiscale entropy analysis . In Proceedings of IEEE INFOCOM. 1107--1115 . Riihijarvi, J., Wellens, M., and Mahonen, P. 2009. Measuring complexity and predictability in networks with multiscale entropy analysis. In Proceedings of IEEE INFOCOM. 1107--1115."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2009.5109450"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1453175.1453191"},{"key":"e_1_2_1_27_1","unstructured":"Sandvine Incorporated. 2011. Global internet phenomena report. http:\/\/www.sandvine.com\/news\/global_broadband_trends.asp.  Sandvine Incorporated. 2011. Global internet phenomena report. http:\/\/www.sandvine.com\/news\/global_broadband_trends.asp."},{"volume-title":"Proceedings of the 19th Annual Joint Conference of the IEEE Computer and Communications Societies (INFOCOM'00)","author":"Sang A.","key":"e_1_2_1_28_1","unstructured":"Sang , A. and Li , S . 2000. A predictability analysis of network traffic . In Proceedings of the 19th Annual Joint Conference of the IEEE Computer and Communications Societies (INFOCOM'00) . 342--351 Sang, A. and Li, S. 2000. A predictability analysis of network traffic. In Proceedings of the 19th Annual Joint Conference of the IEEE Computer and Communications Societies (INFOCOM'00). 342--351"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1002\/sim.2942"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/WETICE.2005.35"},{"key":"e_1_2_1_32_1","unstructured":"Walsworth C. Aben E. Claffy K. and Andersen D. 2009. The CAIDA anonymized 2009 Internet traces - (jan 15). http:\/\/www.caida.org\/data\/passive\/passive_2009_dataset.xml.  Walsworth C. Aben E. Claffy K. and Andersen D. 2009. The CAIDA anonymized 2009 Internet traces - (jan 15). http:\/\/www.caida.org\/data\/passive\/passive_2009_dataset.xml."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/18.382012"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.554723"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080091.1080112"}],"container-title":["ACM Transactions on Modeling and Computer Simulation"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2457459.2457463","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2457459.2457463","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:18:36Z","timestamp":1750234716000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2457459.2457463"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,5]]},"references-count":35,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2013,5]]}},"alternative-id":["10.1145\/2457459.2457463"],"URL":"https:\/\/doi.org\/10.1145\/2457459.2457463","relation":{},"ISSN":["1049-3301","1558-1195"],"issn-type":[{"type":"print","value":"1049-3301"},{"type":"electronic","value":"1558-1195"}],"subject":[],"published":{"date-parts":[[2013,5]]},"assertion":[{"value":"2011-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-05-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}