DocumentCode :
2206510
Title :
Multi-scale entropy and renyi cross entropy based traffic anomaly detection
Author :
Yan, Ruoyu ; Zheng, Qinghua ; Peng, Weimin
Author_Institution :
Dept. of Comput. Sci. & Technol., Xi´´an Jiaotong Univ., Xi´´an, China
fYear :
2008
fDate :
19-21 Nov. 2008
Firstpage :
554
Lastpage :
558
Abstract :
The idea of using entropy measurement to detect anomalies is not a novelty in the research community. But all these entropy-based approaches are single-scale based ¿complexity¿ methods, and don¿t consider temporal and spatial correlation in network traffic. In this paper, multi-scale entropy (MSE) and Renyi cross entropy are introduced to solve these problems. First, a kind of Port-to-Port traffic termed IF-flow in router is defined. Internal traffic matrix can be constructed by IF-flows. Then a new scheme based on MSE and Renyi cross entropy is proposed to detect traffic anomaly existed in IF-flow matrix. MSE is used to detect IF-flow traces in time scales. Renyi cross entropy is used to detect anomaly existed in IF-flow matrix in space and small scale time, and pinpoint IF-flow(s) responsible for entropy change. An improved method to calculate Renyi cross entropy is proposed to reduce false alarm and identify anomaly duration. The experimental results indicate the scheme can detect anomaly accurately in time and space.
Keywords :
computer networks; entropy; matrix algebra; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; IF-flow matrix; Renyi cross entropy; internal traffic matrix; multiscale entropy; network router; network traffic anomaly detection; port-to-port traffic; Computer crime; Computer science; Entropy; Information science; Information theory; Marine technology; Oceans; Sea measurements; Telecommunication traffic; Traffic control; IF-flow; Multi-scale entropy; Renyi cross entropy; Traffic matrix; anomaly detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communication Systems, 2008. ICCS 2008. 11th IEEE Singapore International Conference on
Conference_Location :
Guangzhou
Print_ISBN :
978-1-4244-2423-8
Electronic_ISBN :
978-1-4244-2424-5
Type :
conf
DOI :
10.1109/ICCS.2008.4737245
Filename :
4737245
Link To Document :
بازگشت