DocumentCode
3744800
Title
Mining network traffic anomaly based on adjustable piecewise entropy
Author
Geng Tian;Zhiliang Wang;Xia Yin;Zimu Li;Xingang Shi;Ziyi Lu;Chao Zhou;Yang Yu;Yingya Guo
Author_Institution
Tsinghua National Laboratory for Information Science and Technology (TNList)
fYear
2015
fDate
6/1/2015 12:00:00 AM
Firstpage
299
Lastpage
308
Abstract
Today network traffic anomaly detection is very challenging in a big and constantly changing network, because there are millions of flows being transferred in a network at the same time, and the flow numbers change all the time. Although traditional information entropy has been proved to be an effective metric on network traffic anomaly detection, such a metric shows some limitations in large scale networks with constantly changing flow numbers, and it makes the traditional entropy inefficient for traffic anomaly detection. Another challenge is how to process large-scale traffic data in a scalable way. In this paper, we propose Adjustable Piecewise Entropy for traffic anomaly detection, and implement Adjustable Piecewise Shannon entropy in Hadoop platform with a cluster of five servers in Tsinghua University Campus Network. Furthermore, we analyze and validate Adjustable Piecewise Entropy in both mathematics and experiments. The experiment results show that Adjustable Piecewise Entropy has better performance for traffic anomaly detection.
Keywords
"Entropy","Measurement","Ports (Computers)","Computer crime","IP networks","Feature extraction","Information entropy"
Publisher
ieee
Conference_Titel
Quality of Service (IWQoS), 2015 IEEE 23rd International Symposium on
Type
conf
DOI
10.1109/IWQoS.2015.7404749
Filename
7404749
Link To Document