Network Traffic Analysis with Process Mining: The UPSIDE Case Study

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Vitale, Francesco, Palmiero, Paolo, Rak, Massimiliano, Mazzocca, Nicola
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915844765777920
author Vitale, Francesco
Palmiero, Paolo
Rak, Massimiliano
Mazzocca, Nicola
author_facet Vitale, Francesco
Palmiero, Paolo
Rak, Massimiliano
Mazzocca, Nicola
contents Online gaming is a popular activity involving the adoption of complex systems and network infrastructures. The relevance of gaming, which generates large amounts of market revenue, drove research in modeling network devices' behavior to evaluate bandwidth consumption, predict and sustain high loads, and detect malicious activity. In this context, process mining appears promising due to its ability to combine data-driven analyses with model-based insights. In this paper, we propose a process mining-based method that analyzes gaming network traffic, allowing: unsupervised characterization of different states from gaming network data; encoding such states through process mining into interpretable Petri nets; and classification of gaming network traffic data to identify different video games being played. We apply the method to the UPSIDE case study, involving gaming network data of several devices interacting with two video games: Clash Royale and Rocket League. Results demonstrate that the gaming network behavior can be effectively and interpretably modeled through states represented as Petri nets with sufficient coherence and specificity while maintaining a good classification accuracy of the two different video games.
format Preprint
id arxiv_https___arxiv_org_abs_2512_23718
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Network Traffic Analysis with Process Mining: The UPSIDE Case Study
Vitale, Francesco
Palmiero, Paolo
Rak, Massimiliano
Mazzocca, Nicola
Machine Learning
Networking and Internet Architecture
Online gaming is a popular activity involving the adoption of complex systems and network infrastructures. The relevance of gaming, which generates large amounts of market revenue, drove research in modeling network devices' behavior to evaluate bandwidth consumption, predict and sustain high loads, and detect malicious activity. In this context, process mining appears promising due to its ability to combine data-driven analyses with model-based insights. In this paper, we propose a process mining-based method that analyzes gaming network traffic, allowing: unsupervised characterization of different states from gaming network data; encoding such states through process mining into interpretable Petri nets; and classification of gaming network traffic data to identify different video games being played. We apply the method to the UPSIDE case study, involving gaming network data of several devices interacting with two video games: Clash Royale and Rocket League. Results demonstrate that the gaming network behavior can be effectively and interpretably modeled through states represented as Petri nets with sufficient coherence and specificity while maintaining a good classification accuracy of the two different video games.
title Network Traffic Analysis with Process Mining: The UPSIDE Case Study
topic Machine Learning
Networking and Internet Architecture
url https://arxiv.org/abs/2512.23718