DocumentCode :
2395726
Title :
A flow-based anomaly detection method using entropy and multiple traffic features
Author :
Chang, Shuying ; Qiu, Xuesong ; Gao, Zhipeng ; Qi, Feng ; Liu, Ke
Author_Institution :
State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
fYear :
2010
fDate :
26-28 Oct. 2010
Firstpage :
223
Lastpage :
227
Abstract :
Network traffic anomaly detection is an important component in network security and management domains which can help to improve availability and reliability of networks. This paper proposes a flow-based anomaly detection method with the help of entropy. Using IPFIX, flow records containing multiple traffic features are collected in each time window. With entropy, joint probability space for multiple traffic features is constructed which is the basis of the proposed scheme. The anomaly detection method is composed of two stages. The first stage is to systematically construct the probability distribution of traffic features in normal traffic pattern. In the second stage, to detect abnormal network activities, the improved Kullback-Leibler distance between the observed probability distribution for the multiple traffic features and the forecast distribution which can be achieved by Holt-Winters technique is calculated. The improved Kullback-Leibler distance is a calculation that measures the level of difference of two probability distributions. When the distance exceeds a pre-set threshold, alerts will be generated. Finally, the scheme is demonstrated by experiment and the result shows that this method has high accuracy and low complexity.
Keywords :
entropy; probability; telecommunication network management; telecommunication network reliability; telecommunication security; telecommunication traffic; Holt-Winters technique; IPFIX; Kullback-Leibler distance; entropy; flow record; flow-based anomaly detection method; forecast distribution; multiple traffic feature; network management; network security; network traffic anomaly detection; pre-set threshold; probability distribution; traffic pattern; Feature extraction; Grippers; Monitoring; Holt-Winters; anomaly detection; improved Kullback-Leibler distance; multiple traffic features;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Broadband Network and Multimedia Technology (IC-BNMT), 2010 3rd IEEE International Conference on
Conference_Location :
Beijing
Print_ISBN :
978-1-4244-6769-3
Type :
conf
DOI :
10.1109/ICBNMT.2010.5705084
Filename :
5705084
Link To Document :
بازگشت