Skip to Main content Skip to Navigation
Conference papers

On Detecting Abrupt Changes in Network Entropy Time Series

Abstract : In recent years, much research focused on entropy as a metric describing the “chaos” inherent to network traffic. In particular, network entropy time series turned out to be a scalable technique to detect unexpected behavior in network traffic.In this paper, we propose an algorithm capable of detecting abrupt changes in network entropy time series. Abrupt changes indicate that the underlying frequency distribution of network traffic has changed significantly. Empirical evidence suggests that abrupt changes are often caused by malicious activity such as (D)DoS, network scans and worm activity, just to name a few.Our experiments indicate that the proposed algorithm is able to reliably identify significant changes in network entropy time series. We believe that our approach helps operators of large-scale computer networks in identifying anomalies which are not visible in flow statistics.
Complete list of metadatas

Cited literature [16 references]  Display  Hide  Download

https://hal.inria.fr/hal-01596209
Contributor : Hal Ifip <>
Submitted on : Wednesday, September 27, 2017 - 1:50:34 PM
Last modification on : Wednesday, September 27, 2017 - 1:51:50 PM
Long-term archiving on: : Thursday, December 28, 2017 - 1:52:41 PM

File

978-3-642-24712-5_18_Chapter.p...
Files produced by the author(s)

Licence


Distributed under a Creative Commons Attribution 4.0 International License

Identifiers

Citation

Philipp Winter, Harald Lampesberger, Markus Zeilinger, Eckehard Hermann. On Detecting Abrupt Changes in Network Entropy Time Series. 12th Communications and Multimedia Security (CMS), Oct 2011, Ghent, Belgium. pp.194-205, ⟨10.1007/978-3-642-24712-5_18⟩. ⟨hal-01596209⟩

Share

Metrics

Record views

132

Files downloads

179