Anomaly Detection of Hostile Traffic Based on Network Traffic Distributions

被引:0
|
作者
Kang, Koohong [1 ]
机构
[1] Seowon Univ, Dept Informat & Commun Engn, Cheongju 361742, Chungbuk, South Korea
关键词
Network Traffic Anomaly; Network Traffic Distribution; DoS; Entropy;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Protecting network systems against novel attacks is a pressing problem. In this paper, we propose a new anomaly detection method based on inbound network traffic distributions. For this purpose, we first present; the diverse distributions of TCP/IP protocol header fields at the border router of a real campus network, and then characterize the distributions when well-known denial-of-service (DoS) attacks are present. We show that the distributions give promising baselines for detecting network traffic anomalies. Moreover we introduce the concept of entropy to transform the obtained distribution into a metric of declaring anomaly. Our preliminary explorations indicate that the proposed method is effective at detecting several DoS attacks on the real network.
引用
收藏
页码:781 / 790
页数:10
相关论文
共 50 条
  • [1] Learning rules for anomaly detection of hostile network traffic
    Mahoney, MV
    Chan, PK
    [J]. THIRD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, PROCEEDINGS, 2003, : 601 - 604
  • [2] Network Anomaly Detection based on Traffic Prediction
    Wang, Fengyu
    Gong, Bin
    Hu, Yi
    Zhang, Ningbo
    [J]. 2009 INTERNATIONAL CONFERENCE ON SCALABLE COMPUTING AND COMMUNICATIONS & EIGHTH INTERNATIONAL CONFERENCE ON EMBEDDED COMPUTING, 2009, : 449 - 454
  • [3] Anomaly detection in network traffic
    Duraj, Agnieszka
    Bucki, Pawel
    Drajling, Aleksander
    Makrocki, Robert
    Sipinski, Mateusz
    [J]. PRZEGLAD ELEKTROTECHNICZNY, 2022, 98 (12): : 205 - 208
  • [4] PCA-Based Network Traffic Anomaly Detection
    Meimei Ding
    Hui Tian
    [J]. Tsinghua Science and Technology, 2016, 21 (05) : 500 - 509
  • [5] Network anomaly traffic detection algorithm based on SVM
    Lei, Yang
    [J]. 2017 INTERNATIONAL CONFERENCE ON ROBOTS & INTELLIGENT SYSTEM (ICRIS), 2017, : 217 - 220
  • [6] Network Traffic Anomaly Detection based on Catastrophe Theory
    Xiong, Wei
    Xiong, Naixue
    Yang, Laurence T.
    Vasilakos, Athanasios V.
    Wang, Qian
    Hu, Hanping
    [J]. 2010 IEEE GLOBECOM WORKSHOPS, 2010, : 2070 - 2074
  • [7] Network Traffic Anomaly Detection based on Apache Spark
    Pwint, Phyo Htet
    Shwe, Thanda
    [J]. 2019 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION TECHNOLOGIES (ICAIT), 2019, : 222 - 226
  • [8] Anomaly detection of network traffic based on wavelet packet
    Gao, Jun
    Hu, Guangmin
    Yao, Xingmiao
    Chang, Rocky K. C.
    [J]. 2006 ASIA-PACIFIC CONFERENCE ON COMMUNICATION, VOLS 1 AND 2, 2006, : 660 - 664
  • [9] PCA-Based Network Traffic Anomaly Detection
    Ding, Meimei
    Tian, Hui
    [J]. TSINGHUA SCIENCE AND TECHNOLOGY, 2016, 21 (05) : 500 - 509
  • [10] Anomaly detection based on the dynamic feature of network traffic
    Zhang, Yaxing
    Jin, Shuyuan
    Wang, Yuanzhuo
    Wang, Yanxia
    [J]. ADVANCES IN ENERGY, ENVIRONMENT AND MATERIALS SCIENCE, 2016, : 781 - 789