• DocumentCode
    2002775
  • Title

    Research of Applying Information Entropy and Clustering Technique on Network Traffic Analysis

  • Author

    Du, Xin ; Yang, Yingjie ; Kang, Xiaowen

  • Author_Institution
    Inst. of Electron. Technol., Inf. Eng. Univ., Zhengzhou, China
  • Volume
    2
  • fYear
    2008
  • fDate
    13-17 Dec. 2008
  • Firstpage
    472
  • Lastpage
    476
  • Abstract
    At the present time, most existing network traffic analysis techniques just focus on the traffic volume. But the fact is that most typical network behavior like DoS, port scan and network scan, etc, also induce some feather parameter distribution of network traffic changed usually. In view of this characteristic, this paper proposes a non-supervised analysis technique for network traffic by introducing information entropy and clustering. This analysis technique partitions the unlabeled traffic data into different clusters based on the comparability by analyzing the distribution of some traffic feather parameters. Then it can make sure the network behavior and the host machine that the corresponding behavior happened on by analysis the mode of cluster further.The experimental result indicates that it can help user know the state of network traffic from the parameter distribution and get good effect in distinguishing anomaly by using this technique to analyze network traffic. So it shows that introducing the entropy and clustering can help managers comprehend the changes of traffic state more comprehensive and find out some baleful network behavior.
  • Keywords
    entropy; telecommunication traffic; informatin clustering; information entropy; network traffic analysis; nonsupervised analysis technique; Data analysis; Data mining; Feathers; IP networks; Information analysis; Information entropy; Probability; Statistical analysis; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security, 2008. CIS '08. International Conference on
  • Conference_Location
    Suzhou
  • Print_ISBN
    978-0-7695-3508-1
  • Type

    conf

  • DOI
    10.1109/CIS.2008.132
  • Filename
    4724821