首页> 外文OA文献 >An information-theoretic method for the detection of anomalies in network traffic
【2h】

An information-theoretic method for the detection of anomalies in network traffic

机译:一种用于检测网络流量异常的信息 - 理论方法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Anomaly-based Intrusion Detection is a key research topic in network security due to its ability to face unknown attacks and new security threats. For this reason, many works on the topic have been proposed in the last decade. Nonetheless, an ultimate solution, able to provide a high detection rate with an acceptable false alarm rate, has still to be identified. In this paper we propose a novel intrusion detection system that performs anomaly detection by studying the variation in the entropy associated to the network traffic. To this aim, the traffic is first aggregated by means of random data structures (namely three-dimension reversible sketches) and then the entropy of different traffic descriptors is computed by using several definitions. The experimental results obtained over the MAWILab dataset validate the system and demonstrate the effectiveness of our proposal for a proper set of entropy definitions.
机译:基于异常的入侵检测是由于其面临未知攻击和新的安全威胁,网络安全的关键研究主题。出于这个原因,在过去十年中提出了许多主题的作品。尽管如此,能够提供具有可接受的误报率的高检测率的最终解决方案仍然仍然识别。在本文中,我们提出了一种新颖的入侵检测系统,通过研究与网络流量相关的熵的变化进行异常检测。为此,流量首先通过随机数据结构(即三维可逆草图)来聚合,然后通过使用多个定义来计算不同流量描述符的熵。在Mawilab数据集上获得的实验结果验证了系统,并展示了我们对适当熵定义的提案的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号