BIFM: an effective similar payload attribution approach for cybercriminal detection using bitmap index table and fuzzy matching

Yifan Yang et al.

Computer Journal2026https://doi.org/10.1093/comjnl/bxag022article
AJG 2
Weight
0.50

What the paper says

The payload attribution system has been proposed to analyze network traffic and assist investigators in identifying flows containing specific excerpts to locate criminals and potential victims. However, various attacks or data leakage behaviors can obscure and scatter the crucial portion of flow payloads to evade detection. Although existing payload attribution techniques strive to enhance the data reduction ratio and reduce false positive rates, research on similar payload querying is notably lacking. In this study, we introduce bitmap index table fuzzy matching (BIFM), a method for digesting network traffic to query and trace variants of malicious traffic. Unlike deterministic bitmap-index PAS that require deterministic bit co-occurrence/alignment between the query excerpt and the stored flow bitmap, an assumption violated when payloads are split or jumbled, BIFM overcomes this limitation via progressive relaxation with fuzzy matching and verification. Leveraging the bitmap index table and fuzzy matching, BIFM efficiently identifies flows containing excerpts or their variants (excerpts that change their appearance by splitting or jumbling) by relaxing the matching conditions for candidate malicious flows. To enhance BIFM’s accuracy, we also propose no-shingling and packet caching mechanisms. We extensively evaluate BIFM’s performance using a dataset constructed from real campus network IP-trace data. Our results demonstrate that BIFM outperforms existing state-of-the-art solutions, achieving an accuracy improvement of $\sim $10% without significantly increasing processing time.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1093/comjnl/bxag022

Or copy a formatted citation

@article{yifan2026,
  title        = {{BIFM: an effective similar payload attribution approach for cybercriminal detection using bitmap index table and fuzzy matching}},
  author       = {Yifan Yang et al.},
  journal      = {Computer Journal},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1093/comjnl/bxag022},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

BIFM: an effective similar payload attribution approach for cybercriminal detection using bitmap index table and fuzzy matching

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.