Characterising Payload Entropy in Packet Flows—Baseline Entropy Analysis for Network Anomaly Detection

被引:0
|
作者
Kenyon, Anthony [1 ]
Deka, Lipika [2 ]
Elizondo, David [2 ]
机构
[1] Hyperscalar Ltd., High Wycombe, HP22 4LW, United Kingdom
[2] School of Computer Science and Informatics, De Montfort University, Leicester,LE1 9BH, United Kingdom
来源
Future Internet | 2024年 / 16卷 / 12期
关键词
D O I
10.3390/fi16120470
中图分类号
学科分类号
摘要
The accurate and timely detection of cyber threats is critical to keeping our online economy and data safe. A key technique in early detection is the classification of unusual patterns of network behaviour, often hidden as low-frequency events within complex time-series packet flows. One of the ways in which such anomalies can be detected is to analyse the information entropy of the payload within individual packets, since changes in entropy can often indicate suspicious activity—such as whether session encryption has been compromised, or whether a plaintext channel has been co-opted as a covert channel. To decide whether activity is anomalous, we need to compare real-time entropy values with baseline values, and while the analysis of entropy in packet data is not particularly new, to the best of our knowledge, there are no published baselines for payload entropy across commonly used network services. We offer two contributions: (1) we analyse several large packet datasets to establish baseline payload information entropy values for standard network services, and (2) we present an efficient method for engineering entropy metrics from packet flows from real-time and offline packet data. Such entropy metrics can be included within feature subsets, thus making the feature set richer for subsequent analysis and machine learning applications. © 2024 by the authors.
引用
收藏
相关论文
共 50 条
  • [1] Deep anomaly detection in packet payload
    Liu, Jiaxin
    Song, Xucheng
    Zhou, Yingjie
    Peng, Xi
    Zhang, Yanru
    Liu, Pei
    Wu, Dapeng
    Zhu, Ce
    NEUROCOMPUTING, 2022, 485 : 205 - 218
  • [2] Network anomaly detection using nonextensive entropy
    Ziviani, Artur
    Gomes, Antonio Tadeu A.
    Monsores, Marcelo L.
    Rodrigues, Paulo S. S.
    IEEE COMMUNICATIONS LETTERS, 2007, 11 (12) : 1034 - 1036
  • [3] Entropy-Based Anomaly Detection in a Network
    Shukla, Ajay Shankar
    Maurya, Rohit
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (04) : 1487 - 1501
  • [4] Entropy Based Method for Network Anomaly Detection
    Quan, Qian
    Hong-Yi, Che
    Rui, Zhang
    IEEE 15TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2009, : 189 - 191
  • [5] Network Anomaly Detection Using Parameterized Entropy
    Berezinski, Przemyslaw
    Szpyrka, Marcin
    Jasiul, Bartosz
    Mazur, Michal
    COMPUTER INFORMATION SYSTEMS AND INDUSTRIAL MANAGEMENT, CISIM 2014, 2014, 8838 : 465 - 478
  • [6] Entropy-based Network Anomaly Detection
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    2017 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016, : 334 - 340
  • [7] Entropy-Based Anomaly Detection in a Network
    Ajay Shankar Shukla
    Rohit Maurya
    Wireless Personal Communications, 2018, 99 : 1487 - 1501
  • [8] Adjustable Piecewise Entropy for Network Traffic Anomaly Detection
    Tian, Geng
    Wang, Zhiliang
    Yin, Xia
    Li, Zimu
    Shi, Xingang
    Lu, Ziyi
    Zhou, Chao
    Guo, Yingya
    2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2015, : 59 - 60
  • [9] An Entropy-Based Network Anomaly Detection Method
    Berezinski, Przemyslaw
    Jasiul, Bartosz
    Szpyrka, Marcin
    ENTROPY, 2015, 17 (04) : 2367 - 2408
  • [10] Smart Grid Communication Network Traffic Anomaly Detection Based on Entropy Analysis
    Ruo, Xuesong
    Lv, Chao
    Pei, Pei
    Gao, Minghui
    Wang, Liming
    2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 1082 - 1086