An empirical evaluation of entropy-based traffic anomaly detection

An empirical evaluation of entropy-based traffic anomaly detection
复制标题

DOI:
10.1145/1452520.1452539
复制
发表时间:
2008-10
期刊:
--
影响因子:
--
通讯作者:
George Nychis;Vyas Sekar;D. Andersen;Hyong S. Kim;Hui Zhang
George Nychis;Vyas Sekar;D. Andersen;Hyong S. Kim;Hui Zhang
中科院分区:
其他
文献类型:
--
作者:
George Nychis;Vyas Sekar;D. Andersen;Hyong S. Kim;Hui Zhang

文献摘要

被引文献

相似文献

基于熵的异常检测方法很有吸引力,因为它们比传统的流量分析提供了更细粒度的洞察。虽然以前的工作已经证明了基于熵的异常检测的好处,但很少有人努力全面理解使用基于熵的多种流量分布分析的检测能力。我们考虑两类分布:流头特征(IP地址、端口和流量大小)和行为特征(衡量每个主机与之通信的不同目的/源IP数量的度分布)。我们观察到,地址和端口分布的熵值的时间序列彼此之间具有很强的相关性,并且提供非常相似的异常检测能力。行为和流量大小分布的相关性较低,并检测未在端口和地址分布中显示为异常的事件。使用综合生成异常的进一步分析还表明,端口和地址分布在检测扫描和带宽洪水异常方面的效用有限。基于我们的分析,我们讨论了基于熵的异常检测的重要意义。
Entropy-based approaches for anomaly detection are appealing since they provide more fine-grained insights than traditional traffic volume analysis. While previous work has demonstrated the benefits of entropy-based anomaly detection, there has been little effort to comprehensively understand the detection power of using entropy-based analysis of multiple traffic distributions in conjunction with each other. We consider two classes of distributions: flow-header features (IP addresses, ports, and flow-sizes), and behavioral features (degree distributions measuring the number of distinct destination/source IPs that each host communicates with). We observe that the timeseries of entropy values of the address and port distributions are strongly correlated with each other and provide very similar anomaly detection capabilities. The behavioral and flow size distributions are less correlated and detect incidents that do not show up as anomalies in the port and address distributions. Further analysis using synthetically generated anomalies also suggests that the port and address distributions have limited utility in detecting scan and bandwidth flood anomalies. Based on our analysis, we discuss important implications for entropy-based anomaly detection.