DocumentCode :
1683427
Title :
Comparison of Properties between Entropy and Chi-Square Based Anomaly Detection Method
Author :
Oshima, Shunsuke ; Nakashima, Takuo ; Sueyoshi, Toshinori
Author_Institution :
ICT Center for Learning Support, Kumamoto Nat. Coll. of Technol., Kumamoto, Japan
fYear :
2011
Firstpage :
221
Lastpage :
228
Abstract :
As the typical anomaly detection methods using statistics, entropy and χ2 based method has been researched and reported in terms of their properties for anomaly attacks. In this research, we compare the properties of both methods and discuss the accuracy of detection and the efficiency for different kinds of attacks. Our previous researches have clarified that the source IP address and destination port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of χ2 value using multi statistical variables. The experiments to verify our proposed methods were conducted using source IP address, destination port number and arriving interval of packets. We could extract the following results. Firstly, EMMM method could decrease the value of False-Positive and False-Negative. Secondly, CSDM method could increase the F-metric, which is the evaluation standard for accurate detection. In the experiments using the same condition of parameters such as probability valuables and window width, CSDM method enlarges the F-metric compared to EMMM method.
Keywords :
IP networks; computer network security; entropy; statistical analysis; χ2 based anomaly detection method; CSDM method; EMMM method; anomaly attacks; anomaly packet property; destination port number; entropy based anomaly detection; false-negative value; false-positive value; multistatistical variables; source IP address; Accuracy; Computer crime; Entropy; Equations; Feature extraction; IP networks; Mathematical model; DoS/DDoS detection; Entropy; anomaly detection; chi-square value; statistical approach;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network-Based Information Systems (NBiS), 2011 14th International Conference on
Conference_Location :
Tirana
ISSN :
2157-0418
Print_ISBN :
978-1-4577-0789-6
Electronic_ISBN :
2157-0418
Type :
conf
DOI :
10.1109/NBiS.2011.40
Filename :
6041889
Link To Document :
بازگشت