An Entropy-Based Network Anomaly Detection Method

An Entropy-Based Network Anomaly Detection Method
复制标题

DOI:
10.3390/e17042367
复制
发表时间:
2015-04-01
期刊:
影响因子:
2.7
通讯作者:
Szpyrka, Marcin
Szpyrka, Marcin
中科院分区:
物理与天体物理3区
文献类型:
--
作者:
Berezinski, Przemyslaw;Jasiul, Bartosz;Szpyrka, Marcin

文献摘要

被引文献

相似文献

数据挖掘是计算机科学的一个跨学科的子领域,涉及人工智能、机器学习和统计学的交叉方法。数据挖掘任务之一是异常检测,它是对大量数据进行分析,以确定不符合预期模式的项目、事件或观测。异常检测适用于各种领域,如欺诈检测、故障检测、系统健康监测等,但本文主要关注异常检测在网络入侵检测领域的应用。本文的主要目的是证明一种基于熵的方法适用于基于网络异常模式的现代僵尸网络类恶意软件的检测。这一目标是通过实现以下几点来实现的:(I)提出了一种基于原始熵的网络异常检测方法的概念,(Ii)该方法的实施,(Iii)原始数据集的准备,(Iv)该方法的评价。
Data mining is an interdisciplinary subfield of computer science involving methods at the intersection of artificial intelligence, machine learning and statistics. One of the data mining tasks is anomaly detection which is the analysis of large quantities of data to identify items, events or observations which do not conform to an expected pattern. Anomaly detection is applicable in a variety of domains, e.g., fraud detection, fault detection, system health monitoring but this article focuses on application of anomaly detection in the field of network intrusion detection. The main goal of the article is to prove that an entropy-based approach is suitable to detect modern botnet-like malware based on anomalous patterns in network. This aim is achieved by realization of the following points: (i) preparation of a concept of original entropy-based network anomaly detection method, (ii) implementation of the method, (iii) preparation of original dataset, (iv) evaluation of the method.