Network Anomaly Detection Using Parameterized Entropy - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2014

Network Anomaly Detection Using Parameterized Entropy

Résumé

Entropy-based anomaly detection has recently been extensively studied in order to overcome weaknesses of traditional volume and rule based approaches to network flows analysis. From many entropy measures only Shannon, Titchener and parameterized Renyi and Tsallis entropies have been applied to network anomaly detection. In the paper, our method based on parameterized entropy and supervised learning is presented. With this method we are able to detect a broad spectrum of anomalies with low false positive rate. In addition, we provide information revealing the anomaly type. The experimental results suggest that our method performs better than Shannon-based and volume-based approach.
Fichier principal
Vignette du fichier
978-3-662-45237-0_43_Chapter.pdf (1.5 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01405630 , version 1 (30-11-2016)

Licence

Paternité

Identifiants

Citer

Przemysław Bereziński, Marcin Szpyrka, Bartosz Jasiul, Michał Mazur. Network Anomaly Detection Using Parameterized Entropy. 13th IFIP International Conference on Computer Information Systems and Industrial Management (CISIM), Nov 2014, Ho Chi Minh City, Vietnam. pp.465-478, ⟨10.1007/978-3-662-45237-0_43⟩. ⟨hal-01405630⟩
101 Consultations
698 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More