Learning Entropy - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

Learning Entropy

Lele Zhang
  • Fonction : Auteur
  • PersonId : 1015751
Darryl Veitch
  • Fonction : Auteur
  • PersonId : 855414

Résumé

Entropy has been widely used for anomaly detection in various disciplines. One such is in network attack detection, where its role is to detect significant changes in underlying distribution shape due to anomalous behaviour such as attacks. In this paper, we point out that entropy has significant blind spots, which can be made use by adversaries to evade detection. To illustrate the potential pitfalls, we give an in-principle analysis of network attack detection, in which we design a camouflage technique and show analytically that it can perfectly mask attacks from entropy based detector with low costs in terms of the volume of traffic brought in for camouflage. Finally, we illustrate and apply our technique to both synthetic distributions and ones taken from real traffic traces, and show how attacks undermine the detector.
Fichier principal
Vignette du fichier
978-3-642-20757-0_2_Chapter.pdf (340.11 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01583407 , version 1 (07-09-2017)

Licence

Paternité

Identifiants

Citer

Lele Zhang, Darryl Veitch. Learning Entropy. 10th IFIP Networking Conference (NETWORKING), May 2011, Valencia, Spain. pp.15-27, ⟨10.1007/978-3-642-20757-0_2⟩. ⟨hal-01583407⟩
42 Consultations
60 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More