Loading...
Please wait, while we are loading the content...
Similar Documents
An Empirical Evaluation of Entropy-Based Traffic Anomaly Detection (2008)
| Content Provider | CiteSeerX |
|---|---|
| Author | Sekar, Vyas Zhang, Hui Andersen, David G. Kim, Hyong Nychis, George |
| Abstract | Entropy-based approaches for anomaly detection are appealing since they provide more fine-grained insights than traditional traffic volume analysis. While previous work has demonstrated the benefits of entropy-based anomaly detection, there has been little effort to comprehensively understand the detection power of using entropy-based analysis of multiple traffic distributions in conjunction with each other. We consider two classes of distributions: flow-header features (IP addresses, ports, and flow-sizes), and behavioral features (degree distributions measuring the number of distinct destination/source IPs that each host communicates with). We observe that the timeseries of entropy values of the address and port distributions are strongly correlated with each other and provide very similar anomaly detection capabilities. The behavioral and flow size distributions are less correlated and detect incidents that do not show up as anomalies in the port and address distributions. Further analysis using synthetically generated anomalies also suggests that the port and address distributions have limited utility in detecting scan and bandwidth flood anomalies. Based on our analysis, we discuss important implications for entropy-based anomaly detection. |
| File Format | |
| Publisher Date | 2008-01-01 |
| Access Restriction | Open |
| Subject Keyword | Detect Incident Behavioral Feature Entropy Value Detection Power Little Effort Entropy-based Analysis Address Distribution Traditional Traffic Volume Analysis Empirical Evaluation Distinct Destination Source Ip Flow-header Feature Entropy-based Traffic Anomaly Detection Anomaly Detection Entropy-based Approach Flow Size Distribution Bandwidth Flood Anomaly Important Implication Fine-grained Insight Entropy-based Anomaly Detection Similar Anomaly Detection Capability Multiple Traffic Distribution Degree Distribution Port Distribution |
| Content Type | Text |