DocumentCode :
1490307
Title :
Effective discovery of attacks using entropy of packet dynamics
Author :
Han, Chan-Kyu ; Choi, Hyoung-Kee
Author_Institution :
Sungkyunkwan Univ., Suwon, South Korea
Volume :
23
Issue :
5
fYear :
2009
fDate :
9/1/2009 12:00:00 AM
Firstpage :
4
Lastpage :
12
Abstract :
Network-based attacks are so devastating that they have become major threats to network security. Early yet accurate warning of these attacks is critical for both operators and end users. However, neither speed nor accuracy is easy to achieve because both require effective extraction and interpretation of anomalous patterns from overwhelmingly massive, noisy network traffic. The intrusion detection system presented here is designed to assist in diagnosing and identifying network attacks. This IDS is based on the notion of packet dynamics, rather than packet content, as a way to cope with the increasing complexity of attacks. We employ a concept of entropy to measure time-variant packet dynamics and, further, to extrapolate this entropy to detect network attacks. The entropy of network traffic should vary abruptly once the distinct patterns of packet dynamics embedded in attacks appear. The proposed classifier is evaluated by comparing independent statistics derived from five well-known attacks. Our classifier detects those five attacks with high accuracy and does so in a timely manner.
Keywords :
entropy; security of data; telecommunication security; telecommunication traffic; discovery of attacks; intrusion detection system; network security; network-based attacks; packet dynamics; Bandwidth; Computer crime; Entropy; Intrusion detection; Pattern analysis; Protection; Statistical distributions; Statistics; Telecommunication traffic; Traffic control;
fLanguage :
English
Journal_Title :
Network, IEEE
Publisher :
ieee
ISSN :
0890-8044
Type :
jour
DOI :
10.1109/MNET.2009.5274916
Filename :
5274916
Link To Document :
بازگشت