DocumentCode :
2002775
Title :
Research of Applying Information Entropy and Clustering Technique on Network Traffic Analysis
Author :
Du, Xin ; Yang, Yingjie ; Kang, Xiaowen
Author_Institution :
Inst. of Electron. Technol., Inf. Eng. Univ., Zhengzhou, China
Volume :
2
fYear :
2008
fDate :
13-17 Dec. 2008
Firstpage :
472
Lastpage :
476
Abstract :
At the present time, most existing network traffic analysis techniques just focus on the traffic volume. But the fact is that most typical network behavior like DoS, port scan and network scan, etc, also induce some feather parameter distribution of network traffic changed usually. In view of this characteristic, this paper proposes a non-supervised analysis technique for network traffic by introducing information entropy and clustering. This analysis technique partitions the unlabeled traffic data into different clusters based on the comparability by analyzing the distribution of some traffic feather parameters. Then it can make sure the network behavior and the host machine that the corresponding behavior happened on by analysis the mode of cluster further.The experimental result indicates that it can help user know the state of network traffic from the parameter distribution and get good effect in distinguishing anomaly by using this technique to analyze network traffic. So it shows that introducing the entropy and clustering can help managers comprehend the changes of traffic state more comprehensive and find out some baleful network behavior.
Keywords :
entropy; telecommunication traffic; informatin clustering; information entropy; network traffic analysis; nonsupervised analysis technique; Data analysis; Data mining; Feathers; IP networks; Information analysis; Information entropy; Probability; Statistical analysis; Telecommunication traffic; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Security, 2008. CIS '08. International Conference on
Conference_Location :
Suzhou
Print_ISBN :
978-0-7695-3508-1
Type :
conf
DOI :
10.1109/CIS.2008.132
Filename :
4724821
Link To Document :
بازگشت