Beyond Shannon: Characterizing Internet Traffic with Generalized Entropy Metrics

被引:0
|
作者
Tellenbach, Bernhard [1 ]
Burkhart, Martin [1 ]
Sornette, Didier [2 ]
Maillart, Thomas [2 ]
机构
[1] Swiss Fed Inst Technol, Comp Engn & Networks Lab, Zurich, Switzerland
[2] Swiss Fed Inst Technol, Dept Management Technol & Econom, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Tracking changes in feature distributions is Very important in the domain of network anomaly detection. Unfortunately, these distributions consist of thousands or even millions of data points. This makes tracking, storing and visualizing changes over time a difficult task. A standard technique for capturing and describing distributions in a compact form is the Shannon entropy analysis. Its use for detecting network anomalies has been studied in-depth and several anomaly detection approaches have applied it with considerable success. However, reducing the information about a distribution to a single number deletes important information such as the nature of the change or it might lead to overlooking a large amount of anomalies entirely. In this paper, we show that a generalized form of entropy is better suited to capture changes in traffic features, by exploring different moments. We introduce the Traffic Entropy Spectrum (TES) to analyze changes in traffic feature distributions and demonstrate its ability to characterize the Structure of anomalies using traffic traces from a large ISP.
引用
收藏
页码:239 / +
页数:2
相关论文
共 50 条
  • [1] ROLE OF BOUNDEDNESS IN CHARACTERIZING SHANNON ENTROPY
    DIDERRICH, GT
    [J]. INFORMATION AND CONTROL, 1975, 29 (02): : 149 - 161
  • [2] ON CHARACTERIZING THE SHANNON ENTROPY WITHOUT ASSUMING SYMMETRY
    NATH, P
    KAUR, MM
    [J]. INFORMATION AND CONTROL, 1980, 47 (03): : 213 - 219
  • [3] Metrics for Characterizing Complexity of Network Traffic
    Riihijaervi, Janne
    Maehoenen, Petri
    Wellens, Matthias
    [J]. 2008 INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS, VOLS 1 AND 2, 2008, : 609 - 614
  • [4] Rationally Inattentive Behavior: Characterizing and Generalizing Shannon Entropy
    Caplin, Andrew
    Dean, Mark
    Leahy, John
    [J]. JOURNAL OF POLITICAL ECONOMY, 2022, 130 (06) : 1676 - 1715
  • [5] On generalized entropy and entropic metrics
    Simovici, Dan
    [J]. JOURNAL OF MULTIPLE-VALUED LOGIC AND SOFT COMPUTING, 2007, 13 (4-6) : 295 - 320
  • [6] Generalized Operator Shannon Entropy and Related Operator Inequalities
    Nikoufar, Ismail
    Yanagi, Kenjiro
    [J]. IRANIAN JOURNAL OF SCIENCE, 2023, 47 (04) : 1379 - 1384
  • [7] Modeling and Characterizing Internet Backbone Traffic
    Yang Jie
    He Yang
    Lin Ping
    Cheng Gang
    [J]. CHINA COMMUNICATIONS, 2010, 7 (05) : 49 - 56
  • [8] Generalized Operator Shannon Entropy and Related Operator Inequalities
    Ismail Nikoufar
    Kenjiro Yanagi
    [J]. Iranian Journal of Science, 2023, 47 : 1379 - 1384
  • [9] Generalized Shannon's entropy as generator of local density functionals
    Flores-Gallegos, N.
    [J]. CHEMICAL PHYSICS LETTERS, 2017, 676 : 1 - 5
  • [10] Alternative Entropy Measures and Generalized Khinchin-Shannon Inequalities
    Mondaini, Rubem P.
    de Albuquerque Neto, Simao C.
    [J]. ENTROPY, 2021, 23 (12)