首页> 外文期刊>Computers & Security >An information-theoretic method for the detection of anomalies in network traffic
【24h】

An information-theoretic method for the detection of anomalies in network traffic

机译:一种信息理论的网络流量异常检测方法

获取原文
获取原文并翻译 | 示例
       

摘要

Anomaly-based Intrusion Detection is a key research topic in network security due to its ability to face unknown attacks and new security threats. For this reason, many works on the topic have been proposed in the last decade. Nonetheless, an ultimate solution, able to provide a high detection rate with an acceptable false alarm rate, has still to be identified. In this paper we propose a novel intrusion detection system that performs anomaly detection by studying the variation in the entropy associated to the network traffic. To this aim, the traffic is first aggregated by means of random data structures (namely three-dimension reversible sketches) and then the entropy of different traffic descriptors is computed by using several definitions. The experimental results obtained over the MAWILab dataset validate the system and demonstrate the effectiveness of our proposal for a proper set of entropy definitions.
机译:基于异常的入侵检测由于其面对未知攻击和新的安全威胁的能力而成为网络安全中的关键研究主题。因此,在过去的十年中提出了许多有关该主题的作品。但是,仍然需要确定一种能够提供高检测率和可接受的误报率的最终解决方案。在本文中,我们提出了一种新颖的入侵检测系统,该系统通过研究与网络流量相关的熵的变化来执行异常检测。为此,首先通过随机数据结构(即三维可逆草图)对流量进行聚合,然后使用几种定义来计算不同流量描述符的熵。通过MAWILab数据集获得的实验结果验证了该系统,并证明了我们的建议对于正确的熵定义集的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号