• DocumentCode
    3744800
  • Title

    Mining network traffic anomaly based on adjustable piecewise entropy

  • Author

    Geng Tian;Zhiliang Wang;Xia Yin;Zimu Li;Xingang Shi;Ziyi Lu;Chao Zhou;Yang Yu;Yingya Guo

  • Author_Institution
    Tsinghua National Laboratory for Information Science and Technology (TNList)
  • fYear
    2015
  • fDate
    6/1/2015 12:00:00 AM
  • Firstpage
    299
  • Lastpage
    308
  • Abstract
    Today network traffic anomaly detection is very challenging in a big and constantly changing network, because there are millions of flows being transferred in a network at the same time, and the flow numbers change all the time. Although traditional information entropy has been proved to be an effective metric on network traffic anomaly detection, such a metric shows some limitations in large scale networks with constantly changing flow numbers, and it makes the traditional entropy inefficient for traffic anomaly detection. Another challenge is how to process large-scale traffic data in a scalable way. In this paper, we propose Adjustable Piecewise Entropy for traffic anomaly detection, and implement Adjustable Piecewise Shannon entropy in Hadoop platform with a cluster of five servers in Tsinghua University Campus Network. Furthermore, we analyze and validate Adjustable Piecewise Entropy in both mathematics and experiments. The experiment results show that Adjustable Piecewise Entropy has better performance for traffic anomaly detection.
  • Keywords
    "Entropy","Measurement","Ports (Computers)","Computer crime","IP networks","Feature extraction","Information entropy"
  • Publisher
    ieee
  • Conference_Titel
    Quality of Service (IWQoS), 2015 IEEE 23rd International Symposium on
  • Type

    conf

  • DOI
    10.1109/IWQoS.2015.7404749
  • Filename
    7404749