Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Artificial Intelligence and Robotics (61)
- Medicine and Health Sciences (53)
- Graphics and Human Computer Interfaces (35)
- Engineering (28)
- Social and Behavioral Sciences (28)
-
- Theory and Algorithms (23)
- Data Science (22)
- Arts and Humanities (18)
- Other Computer Sciences (17)
- Information Security (13)
- Computer Engineering (12)
- Health Information Technology (12)
- Life Sciences (11)
- Art and Design (10)
- Psychology (10)
- Statistics and Probability (10)
- Interactive Arts (9)
- Mathematics (9)
- Applied Mathematics (8)
- OS and Networks (8)
- Cybersecurity (7)
- Interdisciplinary Arts and Media (7)
- Numerical Analysis and Scientific Computing (7)
- Software Engineering (7)
- Systems Architecture (7)
- Applied Statistics (5)
- Databases and Information Systems (5)
- Education (5)
- Keyword
-
- Mobile computing (58)
- Security (58)
- Wireless (46)
- Network (38)
- Privacy (38)
-
- Mhealth (35)
- Parallel computing (27)
- File system (26)
- Distributed computing (25)
- Ubicomp (25)
- Sensors (24)
- Parallel-io (21)
- Wearable (20)
- Machine Learning (18)
- Machine learning (17)
- Mobile-agent (16)
- MHealth (13)
- Deep learning (12)
- Healthcare (12)
- Natural Language Processing (10)
- AI (9)
- Artificial Intelligence (8)
- Intrusion detection (8)
- Mobile (8)
- Mobile health (8)
- Natural language processing (7)
- Algorithms (6)
- Amulet (6)
- Authentication (6)
- Interpretability (6)
- Publication Year
- Publication
-
- Computer Science Technical Reports (374)
- Dartmouth College Undergraduate Theses (225)
- Dartmouth Scholarship (222)
- Dartmouth College Ph.D Dissertations (109)
- Computer Science Senior Theses (83)
-
- Dartmouth College Master’s Theses (78)
- Other Faculty Materials (4)
- ENGS 88 Honors Thesis (AB Students) (2)
- Cognitive Science Senior Theses (1)
- Independent Student Projects and Publications (1)
- Linguistics Undergraduate Senior Theses (1)
- Physics and Astronomy Undergraduate Senior Theses (1)
- Quantitative Social Science Undergraduate Senior Theses (1)
- Wetterhahn Science Symposium Posters (1)
- Wetterhahn Science Symposium Posters 2018 (1)
- Publication Type
- File Type
Articles 511 - 540 of 1104
Full-Text Articles in Computer Sciences
Dartmouth Internet Security Testbed (Dist): Building A Campus-Wide Wireless Testbed, Sergey Bratus, David Kotz, Keren Tan, William Taylor, Anna Shubina, Bennet Vance, Michael E. Locasto
Dartmouth Internet Security Testbed (Dist): Building A Campus-Wide Wireless Testbed, Sergey Bratus, David Kotz, Keren Tan, William Taylor, Anna Shubina, Bennet Vance, Michael E. Locasto
Dartmouth Scholarship
We describe our experiences in deploying a campus-wide wireless security testbed. The testbed gives us the capability to monitor security-related aspects of the 802.11 MAC layer in over 200 diverse campus locations. We describe both the technical and the social challenges of designing, building, and deploying such a system, which, to the best of our knowledge, is the largest such testbed in academia (with the UCSD's Jigsaw infrastructure a close competitor). In this paper we focus on the \em testbed setup, rather than on the experimental data and results.
Hardware-Assisted Secure Computation, Alexander Iliev
Hardware-Assisted Secure Computation, Alexander Iliev
Dartmouth College Ph.D Dissertations
The theory community has worked on Secure Multiparty Computation (SMC) for more than two decades, and has produced many protocols for many settings. One common thread in these works is that the protocols cannot use a Trusted Third Party (TTP), even though this is conceptually the simplest and most general solution. Thus, current protocols involve only the direct players---we call such protocols self-reliant. They often use blinded boolean circuits, which has several sources of overhead, some due to the circuit representation and some due to the blinding. However, secure coprocessors like the IBM 4758 have actual security properties similar to …
Distributed Monitoring Of Conditional Entropy For Network Anomaly Detection, Chrisil Arackaparambil, Sergey Bratus, Joshua Brody, Anna Shubina
Distributed Monitoring Of Conditional Entropy For Network Anomaly Detection, Chrisil Arackaparambil, Sergey Bratus, Joshua Brody, Anna Shubina
Computer Science Technical Reports
Monitoring the empirical Shannon entropy of a feature in a network packet stream has previously been shown to be useful in detecting anomalies in the network traffic. Entropy is an information-theoretic statistic that measures the variability of the feature under consideration. Anomalous activity in network traffic can be captured by detecting changes in this variability. There are several challenges, however, in monitoring this statistic. Computing the statistic efficiently is non-trivial. Further, when monitoring multiple features, the streaming algorithms proposed previously would likely fail to keep up with the ever-increasing channel bandwidth of network traffic streams. There is also the concern …
Data For Cybersecurity Research: Process And ‘Wish List’, Jean Camp, Lorrie Cranor, Nick Feamster, Joan Feigenbaum, Stephanie Forrest, David Kotz, Wenke Lee, Patrick Lincoln, Vern Paxson, Mike Reiter, Ron Rivest, William Sanders, Stefan Savage, Sean Smith, Eugene Spafford, Sal Stolfo
Data For Cybersecurity Research: Process And ‘Wish List’, Jean Camp, Lorrie Cranor, Nick Feamster, Joan Feigenbaum, Stephanie Forrest, David Kotz, Wenke Lee, Patrick Lincoln, Vern Paxson, Mike Reiter, Ron Rivest, William Sanders, Stefan Savage, Sean Smith, Eugene Spafford, Sal Stolfo
Other Faculty Materials
This document identifies data needs of the security research community. This document is in response to a request for a “data wish list”. Because specific data needs will evolve in conjunction with evolving threats and research problems, we augment the wish list with commentary about some of the broader issues for data usage.
Automated Tracking Of Dividing Nuclei In Microscopy Videos Of Living Cells, Evan L. Tice
Automated Tracking Of Dividing Nuclei In Microscopy Videos Of Living Cells, Evan L. Tice
Dartmouth College Undergraduate Theses
Many cell biologists perform analysis of multinucleated cell data in order to better under- stand the mechanisms that regulate cell division. Sbalzarini, et al., have developed methods for automatically tracking nuclei in cell data in order to aid in this time-consuming analysis. In this paper, we present an implementation of the Sbalzarini tracking algorithm, introduce a new algorithm we developed which is able to identify mitosis events, and present other software tools we have developed to aid in the automated detection of nucleus data.
Developing An Improved, Web-Based Classroom Response System With Web Services, Oleg B. Seletsky
Developing An Improved, Web-Based Classroom Response System With Web Services, Oleg B. Seletsky
Dartmouth College Undergraduate Theses
Classroom Response Systems (CRS) are an in-class technology used to poll students and instantly display an aggregate representation of their responses. CRS have been around since the 1970s and have become increasingly more popular in higher education lecture halls. Even though technology, specifically computers and communications, has improved significantly since the 1970s, CRS have remained surprisingly unchanged. The purpose of this project was to develop an innovative web-based CRS using web services. The web-based aspect utilizes Dartmouth's wireless campus while the web services back-end makes the product more extensible. Lastly, we added a set of out-of-class learning tools for students …
The Effects Of Introspection On Computer Security Policies, Stephanie A. Trudeau
The Effects Of Introspection On Computer Security Policies, Stephanie A. Trudeau
Dartmouth College Undergraduate Theses
What does it mean to be an expert? And what makes an expert more capable than a non-expert when it comes to evaluating and articulating their impressions about something as commonly practiced as food tasting? How do we explain those behaviors that humans perform very well, but don't quite know why? Studies have shown that there exists a class of activities that we as humans execute well intuitively, but that we perform much worse upon introspection. Evidence supports the claim that the act of introspection actually causes us to do more poorly at these tasks. My goal is to apply …
An Information Complexity Approach To The Inner Product Problem, William B. Henderson-Frost
An Information Complexity Approach To The Inner Product Problem, William B. Henderson-Frost
Dartmouth College Undergraduate Theses
We prove a lower bound of the randomized communication complexity of the inner product function on the uniform distribution.
Hawk: 3d Gestured-Based Interactive Bird Flight Simulation, Thomas Yale Eastman
Hawk: 3d Gestured-Based Interactive Bird Flight Simulation, Thomas Yale Eastman
Dartmouth College Undergraduate Theses
Control interfaces provide the most tangible connection between human users and computer software. This link is especially important in interactive real-time applications, like games and simulations, because users desire efficient controls that allow them to maximize their interactivity and immersion with the software. Traditionally, interfaces have been largely limited to keyboards and mice. Recently, however, technological advances have made motion-sensitive devices not only available to mainstream consumers but have also lifted restrictions limiting devices to two-dimensional motion. This work presents a 3-dimensional motion-sensitive interface alongside a natural application. Players can control a soaring red-tailed hawk and perform various intuitive flight …
Applying Domain Knowledge From Structured Citation Formats To Text And Data Mining: Examples Using The Cite Architecture, D Neel Smith, Gabriel A. Weaver
Applying Domain Knowledge From Structured Citation Formats To Text And Data Mining: Examples Using The Cite Architecture, D Neel Smith, Gabriel A. Weaver
Computer Science Technical Reports
Domain knowledge expressed in structured citation formats can be exploited in data mining. We propose four structural properties of canonically cited texts, then look at to two classic problems in the study of the scholia, or ancient scholarly commentary, found in the manuscripts of the Iliad. We cluster citations of scholia to analyze their distribution in different manuscripts; this leads to a revised view of how the manuscripts' scribes drew on their source material. Correlated frequencies of named entities suggest that one group of manuscripts had access to material more closely based on the work of the greatest Hellenistic editor …
A Computational Framework For Certificate Policy Operations, Gabriel A. Weaver, Scott Rea, Sean W. Smith
A Computational Framework For Certificate Policy Operations, Gabriel A. Weaver, Scott Rea, Sean W. Smith
Computer Science Technical Reports
The trustworthiness of any Public Key Infrastructure (PKI) rests upon the expectations for trust, and the degree to which those ex- pectations are met. Policies, whether implicit as in PGP and SDSI/SPKI or explicitly required as in X.509, document expectations for trust in a PKI. The widespread use of X.509 in the context of global e-Science infrastructures, financial institutions, and the U.S. Federal government demands efficient, transparent, and reproducible policy decisions. Since current manual processes fall short of these goals, we designed, built, and tested computational tools to process the citation schemes of X.509 certificate policies defined in RFC 2527 …
Surface Reconstruction Through Time, Leeann T. Brash
Surface Reconstruction Through Time, Leeann T. Brash
Dartmouth College Master’s Theses
Surface reconstruction is an area of computational geometry that has been progressing rapidly over the last decade. Current algorithms and their implementations can reconstruct surfaces from a variety of input and the accuracy and precision improve with each new development. These all make use of various heuristics to achieve a reconstruction. Much of this work consists of reconstructing a still object from point samples taken from the object's surface. We examine reconstructing an n-dimensional object and its motion by treating time as an (n + 1)st axis. Our input consists of (n-1)-dimensional scans taken over time and at di?erent positions …
Deamon: Energy-Efficient Sensor Monitoring, Minho Shin, Patrick Tsang, David Kotz, Cory Cornelius
Deamon: Energy-Efficient Sensor Monitoring, Minho Shin, Patrick Tsang, David Kotz, Cory Cornelius
Dartmouth Scholarship
In people-centric opportunistic sensing, people offer their mobile nodes (such as smart phones) as platforms for collecting sensor data. A sensing application distributes sensing `tasks,' which specify what sensor data to collect and under what conditions to report the data back to the application. To perform a task, mobile nodes may use on-board sensors, a body-area network of personal sensors, or sensors from neighboring nodes that volunteer to contribute their sensing resources. In all three cases, continuous sensor monitoring can drain a node's battery. \par We propose DEAMON (Distributed Energy-Aware MONitoring), an energy-efficient distributed algorithm for long-term sensor monitoring. Our …
Autoscopy: Detecting Pattern-Searching Rootkits Via Control Flow Tracing, Ashwin Ramaswamy
Autoscopy: Detecting Pattern-Searching Rootkits Via Control Flow Tracing, Ashwin Ramaswamy
Dartmouth College Master’s Theses
Traditional approaches to rootkit detection assume the execution of code at a privilege level below that of the operating system kernel, with the use of virtual machine technologies to enable the detection system itself to be immune from the virus or rootkit code. In this thesis, we approach the problem of rootkit detection from the standpoint of tracing and instrumentation techniques, which work from within the kernel and also modify the kernel's run-time state to detect aberrant control flows. We wish to investigate the role of emerging tracing frameworks (Kprobes, DTrace etc.) in enforcing operating system security without the reliance …
Dynamic Universal Accumulators For Ddh Groups And Their Application To Attribute-Based Anonymous Credential Systems, Man Ho Au, Patrick P. Tsang, Willy Susilo, Yi Mu
Dynamic Universal Accumulators For Ddh Groups And Their Application To Attribute-Based Anonymous Credential Systems, Man Ho Au, Patrick P. Tsang, Willy Susilo, Yi Mu
Computer Science Technical Reports
We present the first dynamic universal accumulator that allows (1) the accumulation of elements in a DDH-hard group G and (2) one who knows x such that y=g^x has --- or has not --- been accumulated, where g generates G, to efficiently prove her knowledge of such x in zero knowledge, and hence without revealing, e.g., x or y. We introduce the Attribute-Based Anonymous Credential System (ABACS), which allows the verifier to authenticate anonymous users according to any access control policy expressible as a formula of possibly negated boolean user attributes. We construct the system from our accumulator.
Authenticated Streamwise On-Line Encryption, Patrick P. Tsang, Rouslan V. Solomakhin, Sean W. Smith
Authenticated Streamwise On-Line Encryption, Patrick P. Tsang, Rouslan V. Solomakhin, Sean W. Smith
Computer Science Technical Reports
In Blockwise On-line Encryption, encryption and decryption return an output block as soon as the next input block is received. In this paper, we introduce Authenticated Streamwise On-line Encryption (ASOE), which operates on plaintexts and ciphertexts as streams of arbitrary length (as opposed to fixed-sized blocks), and thus significantly reduces message expansion and end-to-end latency. Also, ASOE provides data authenticity as an option. ASOE can therefore be used to efficiently secure resource-constrained communications with real-time requirements such as those in the electric power grid and wireless sensor networks. We investigate and formalize ASOE's strongest achievable notion of security, and present …
Approximability Of The Unsplittable Flow Problem On Trees, Chrisil Arackaparambil, Amit Chakrabarti, Chien-Chung Huang
Approximability Of The Unsplittable Flow Problem On Trees, Chrisil Arackaparambil, Amit Chakrabarti, Chien-Chung Huang
Computer Science Technical Reports
We consider the approximability of the Unsplittable Flow Problem (UFP) on tree graphs, and give a deterministic quasi-polynomial time approximation scheme for the problem when the number of leaves in the tree graph is at most poly-logarithmic in $n$ (the number of demands), and when all edge capacities and resource requirements are suitably bounded. Our algorithm generalizes a recent technique that obtained the first such approximation scheme for line graphs. Our results show that the problem is not APX-hard for such graphs unless NP \subseteq DTIME(2^{polylog(n)}). Further, a reduction from the Demand Matching Problem shows that UFP is APX-hard when …
A Combined Routing Method For Ad Hoc Wireless Networks, Soumendra Nanda, Zhenhui Jiang, David Kotz
A Combined Routing Method For Ad Hoc Wireless Networks, Soumendra Nanda, Zhenhui Jiang, David Kotz
Computer Science Technical Reports
Several simulation and real world studies show that certain ad hoc routing protocols perform better than others under specific mobility and traffic patterns. In order to exploit this phenomena, we propose a novel approach to adapt a network to changing conditions; we introduce "a combined routing method" that allows the network to seamlessly swap from one routing protocol to another protocol dynamically, while routing continues uninterrupted. By creating a thin new virtual layer, we enable each node in the ad hoc wireless network notify each other about the protocol swap and we do not make any changes to existing routing …
Opportunistic Sensing: Security Challenges For The New Paradigm, Apu Kapadia, David Kotz, Nikos Triandopoulos
Opportunistic Sensing: Security Challenges For The New Paradigm, Apu Kapadia, David Kotz, Nikos Triandopoulos
Dartmouth Scholarship
We study the security challenges that arise in Opportunistic people-centric sensing, a new sensing paradigm leveraging humans as part of the sensing infrastructure. Most prior sensor-network research has focused on collecting and processing environmental data using a static topology and an application-aware infrastructure, whereas opportunistic sensing involves collecting, storing, processing and fusing large volumes of data related to everyday human activities. This highly dynamic and mobile setting, where humans are the central focus, presents new challenges for information security, because data originates from sensors carried by people— not tiny sensors thrown in the forest or attached to animals. In this …
Topological Structures In The Equities Market Network, Gregory Leibon, Scott Pauls, Daniel Rockmore, Robert Savell
Topological Structures In The Equities Market Network, Gregory Leibon, Scott Pauls, Daniel Rockmore, Robert Savell
Dartmouth Scholarship
We present a new method for articulating scale-dependent topological descriptions of the network structure inherent in many complex systems. The technique is based on “partition decoupled null models,” a new class of null models that incorporate the interaction of clustered partitions into a random model and generalize the Gaussian ensemble. As an application, we analyze a correlation matrix derived from 4 years of close prices of equities in the New York Stock Exchange (NYSE) and National Association of Securities Dealers Automated Quotation (NASDAQ). In this example, we expose (i) a natural structure composed of 2 interacting partitions of …
Nymble: Blocking Misbehaving Users In Anonymizing Networks, Patrick P. Tsang, Apu Kapadia, Cory Cornelius, Sean W. Smith
Nymble: Blocking Misbehaving Users In Anonymizing Networks, Patrick P. Tsang, Apu Kapadia, Cory Cornelius, Sean W. Smith
Computer Science Technical Reports
Anonymizing networks such as Tor allow users to access Internet services privately by using a series of routers to hide the client's IP address from the server. The success of such networks, however, has been limited by users employing this anonymity for abusive purposes such as defacing popular websites. Website administrators routinely rely on IP-address blocking for disabling access to misbehaving users, but blocking IP addresses is not practical if the abuser routes through an anonymizing network. As a result, administrators block \emph{all} known exit nodes of anonymizing networks, denying anonymous access to misbehaving and behaving users alike. To address …
Functional Monitoring Without Monotonicity, Chrisil Arackaparambil, Joshua Brody, Amit Chakrabarti
Functional Monitoring Without Monotonicity, Chrisil Arackaparambil, Joshua Brody, Amit Chakrabarti
Computer Science Technical Reports
The notion of distributed functional monitoring was recently introduced by Cormode, Muthukrishnan and Yi to initiate a formal study of the communication cost of certain fundamental problems arising in distributed systems, especially sensor networks. In this model, each of k sites reads a stream of tokens and is in communication with a central coordinator, who wishes to continuously monitor some function f of \sigma, the union of the k streams. The goal is to minimize the number of bits communicated by a protocol that correctly monitors f(\sigma), to within some small error. As in previous work, we focus on a …
Digital Image Ballistics From Jpeg Quantization: A Followup Study, Hany Farid
Digital Image Ballistics From Jpeg Quantization: A Followup Study, Hany Farid
Computer Science Technical Reports
The lossy JPEG compression scheme employs a quantization table that controls the amount of compression achieved. Because different cameras typically employ different tables, a comparison of an image's quantization scheme to a database of known cameras affords a simple technique for confirming or denying an image's source. This report describes the analysis of quantization tables extracted from 1,000,000 images downloaded from Flickr.com.
Group-Aware Stream Filtering For Bandwidth-Efficient Data Dissemination, Ming Li, David Kotz
Group-Aware Stream Filtering For Bandwidth-Efficient Data Dissemination, Ming Li, David Kotz
Dartmouth Scholarship
In this paper we are concerned with disseminating high-volume data streams to many simultaneous applications over a low-bandwidth wireless mesh network. For bandwidth efficiency, we propose a group-aware stream filtering approach, used in conjunction with multicasting, that exploits two overlooked, yet important, properties of these applications: 1) many applications can tolerate some degree of “slack” in their data quality requirements, and 2) there may exist multiple subsets of the source data satisfying the quality needs of an application. We can thus choose the “best alternative” subset for each application to maximize the data overlap within the group to best benefit …
Toward Evaluating Lighting Design Interface Paradigms For Novice Users, William Brandon Kerr, Fabio Pellacini
Toward Evaluating Lighting Design Interface Paradigms For Novice Users, William Brandon Kerr, Fabio Pellacini
Computer Science Technical Reports
Lighting design is a complex and fundamental task in computer cinematography, involving adjustment of light parameters to define final scene appearance. Many lighting interfaces have been proposed to improve lighting design work flow. These paradigms exist in three paradigm categories: direct light parameter manipulation, indirect light feature manipulation (e.g., shadow dragging), and goal-based optimization of light through painting. To this date, no formal evaluation of the relative effectiveness of these methods has been performed. In this paper, we present a first step toward evaluating the three paradigms in the form of a user study with novice users. We focus our …
Blac: Revoking Repeatedly Misbehaving Anonymous Users Without Relying On Ttps, Patrick P. Tsang, Man Ho Au, Apu Kapadia, Sean W. Smith
Blac: Revoking Repeatedly Misbehaving Anonymous Users Without Relying On Ttps, Patrick P. Tsang, Man Ho Au, Apu Kapadia, Sean W. Smith
Computer Science Technical Reports
Several credential systems have been proposed in which users can authenticate to service providers anonymously. Since anonymity can give users the license to misbehave, some variants allow the selective deanonymization (or linking) of misbehaving users upon a complaint to a trusted third party (TTP). The ability of the TTP to revoke a user's privacy at any time, however, is too strong a punishment for misbehavior. To limit the scope of deanonymization, systems have been proposed in which users are deanonymized if they authenticate ``too many times,'' such as ``double spending'' with electronic cash. While useful in some applications, it is …
The Changing Usage Of A Mature Campus-Wide Wireless Network, Tristan Henderson, David Kotz, Ilya Abyzov
The Changing Usage Of A Mature Campus-Wide Wireless Network, Tristan Henderson, David Kotz, Ilya Abyzov
Dartmouth Scholarship
Wireless Local Area Networks (WLANs) are now commonplace on many academic and corporate campuses. As "Wi-Fi" technology becomes ubiquitous, it is increasingly important to understand trends in the usage of these networks. This paper analyzes an extensive network trace from a mature 802.11 WLAN, including more than 550 access points and 7000 users over seventeen weeks. We employ several measurement techniques, including syslog messages, telephone records, SNMP polling and tcpdump packet captures. This is the largest WLAN study to date, and the first to look at a mature WLAN. We compare this trace to a trace taken after the network's …
Lzfuzz: A Fast Compression-Based Fuzzer For Poorly Documented Protocols, Sergey Bratus, Axel Hansen, Anna Shubina
Lzfuzz: A Fast Compression-Based Fuzzer For Poorly Documented Protocols, Sergey Bratus, Axel Hansen, Anna Shubina
Computer Science Technical Reports
Real-world infrastructure offers many scenarios where protocols (and other details) are not released due to being considered too sensitive or for other reasons. This situation makes it hard to apply fuzzing techniques to test their security and reliability, since their full documentation is only available to their developers, and domain developer expertise does not necessarily intersect with fuzz-testing expertise (nor deployment responsibility). State-of-the-art fuzzing techniques, however, work best when protocol specifications are available. Still, operators whose networks include equipment communicating via proprietary protocols should be able to reap the benefits of fuzz-testing them. In particular, administrators should be able to …
Detecting Kernel Rootkits, Ashwin Ramaswamy
Detecting Kernel Rootkits, Ashwin Ramaswamy
Computer Science Technical Reports
Kernel rootkits are a special category of malware that are deployed directly in the kernel and hence have unmitigated reign over the functionalities of the kernel itself. We seek to detect such rootkits that are deployed in the real world by first observing how the majority of kernel rootkits operate. To this end, comparable to how rootkits function in the real world, we write our own kernel rootkit that manipulates the network driver, thus giving us control over all packets sent into the network. We then implement a mechanism to thwart the attacks of such rootkits by noticing that a …
Streaming Estimation Of Information-Theoretic Metrics For Anomaly Detection (Extended Abstract), Sergey Bratus, Joshua Brody, David Kotz, Anna Shubina
Streaming Estimation Of Information-Theoretic Metrics For Anomaly Detection (Extended Abstract), Sergey Bratus, Joshua Brody, David Kotz, Anna Shubina
Dartmouth Scholarship
Information-theoretic metrics hold great promise for modeling traffic and detecting anomalies if only they could be computed in an efficient, scalable ways. Recent advances in streaming estimation algorithms give hope that such computations can be made practical. We describe our work in progress that aims to use streaming algorithms on 802.11a/b/g link layer (and above) features and feature pairs to detect anomalies.