• DocumentCode
    2157422
  • Title

    Detection of anomalous packet traffic via entropy

  • Author

    Lawniczak, Anna T. ; Wu, Hao ; Di Stefano, Bruno N.

  • Author_Institution
    Dept. of Math. & Stat., Univ. of Guelph, Guelph, ON
  • fYear
    2009
  • fDate
    3-6 May 2009
  • Firstpage
    137
  • Lastpage
    141
  • Abstract
    We study if information entropy of packet traffic passing through selected set of routers may detect anomalous packet traffic (e.g., distributed denial-of-service (DDoS) attacks) in a packet switching network (PSN) model. Given a certain PSN model setup (i.e., topology, routing algorithm, and source load value) a ldquonaturalrdquo entropy profile of normal packet traffic monitored at selected routers characterizes normal operation of PSN model. When entropy of packet traffic deviates significantly from this ldquonaturalrdquo profile it means that some anomaly in packet traffic emerges. Our simulations of ping DDoS attacks show that after start of attacks the entropy of packet traffics monitored network-wide at relatively small sets of routers may significantly drop and that it is easier to detect these drops if static routing is used instead of dynamic routing. Thus, for detection of DDoS attacks and other anomalous packet traffic information entropy of packet traffic monitored network-wide at properly selected routers can be a useful tool.
  • Keywords
    entropy; packet switching; telecommunication network routing; telecommunication security; telecommunication traffic; DDoS attack; anomalous packet traffic; distributed denial-of-service; information entropy; packet switching network; static routing; Computer crime; Cost function; Information entropy; Internet; Monitoring; Network topology; Packet switching; Routing; Telecommunication traffic; Traffic control; detection; distributed denial of service attack; entropy; packet switching network;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electrical and Computer Engineering, 2009. CCECE '09. Canadian Conference on
  • Conference_Location
    St. John´s, NL
  • ISSN
    0840-7789
  • Print_ISBN
    978-1-4244-3509-8
  • Electronic_ISBN
    0840-7789
  • Type

    conf

  • DOI
    10.1109/CCECE.2009.5090107
  • Filename
    5090107