DocumentCode
3259468
Title
Entropy-based profiling of network traffic for detection of security attack
Author
Lee, Tsern-Huei ; He, Jyun-De
Author_Institution
Dept. of Commun. Eng., Nat. Chiao Tung Univ., Hsinchu, Taiwan
fYear
2009
fDate
23-26 Jan. 2009
Firstpage
1
Lastpage
5
Abstract
Network security has become a major concern in recent years. In this research, we present an entropy-based network traffic profiling scheme for detecting security attacks. The proposed scheme consists of two stages. The purpose of the first stage is to systematically construct the probability distribution of relative uncertainty for normal network traffic behavior. In the second stage, we use the chi-square goodness-of-fit test, a calculation that measures the level of difference of two probability distributions, to detect abnormal network activities. The probability distribution of the relative uncertainty for short-term network behavior is compared with that of the long-term profile constructed in the first stage. We demonstrate the performance of our proposed scheme for DoS attacks with the dataset derived from KDD CUP 1999. Experimental results show that our proposed scheme achieves high accuracy if the features are selected appropriately.
Keywords
Internet; computer network security; entropy; statistical distributions; telecommunication traffic; Internet; chi-square goodness-of-fit test; entropy-based network traffic profiling scheme; probability distribution; relative uncertainty; security attack detection; short-term network behavior; Communication system security; Computer crime; Data security; Entropy; Internet; Intrusion detection; National security; Probability distribution; Telecommunication traffic; Testing; anomaly detection; chi-square; entropy; profiling;
fLanguage
English
Publisher
ieee
Conference_Titel
TENCON 2009 - 2009 IEEE Region 10 Conference
Conference_Location
Singapore
Print_ISBN
978-1-4244-4546-2
Electronic_ISBN
978-1-4244-4547-9
Type
conf
DOI
10.1109/TENCON.2009.5396211
Filename
5396211
Link To Document