Title :
Mining network traffic anomaly based on adjustable piecewise entropy
Author :
Geng Tian;Zhiliang Wang;Xia Yin;Zimu Li;Xingang Shi;Ziyi Lu;Chao Zhou;Yang Yu;Yingya Guo
Author_Institution :
Tsinghua National Laboratory for Information Science and Technology (TNList)
fDate :
6/1/2015 12:00:00 AM
Abstract :
Today network traffic anomaly detection is very challenging in a big and constantly changing network, because there are millions of flows being transferred in a network at the same time, and the flow numbers change all the time. Although traditional information entropy has been proved to be an effective metric on network traffic anomaly detection, such a metric shows some limitations in large scale networks with constantly changing flow numbers, and it makes the traditional entropy inefficient for traffic anomaly detection. Another challenge is how to process large-scale traffic data in a scalable way. In this paper, we propose Adjustable Piecewise Entropy for traffic anomaly detection, and implement Adjustable Piecewise Shannon entropy in Hadoop platform with a cluster of five servers in Tsinghua University Campus Network. Furthermore, we analyze and validate Adjustable Piecewise Entropy in both mathematics and experiments. The experiment results show that Adjustable Piecewise Entropy has better performance for traffic anomaly detection.
Keywords :
"Entropy","Measurement","Ports (Computers)","Computer crime","IP networks","Feature extraction","Information entropy"
Conference_Titel :
Quality of Service (IWQoS), 2015 IEEE 23rd International Symposium on
DOI :
10.1109/IWQoS.2015.7404749