Anomaly Detection and Visualization using Fisher Discriminant Clustering of Network Entropy

被引:0
|
作者
Celenk, Mehmet [1 ]
Conley, Thomas [1 ]
Willis, John [1 ]
Graham, James [1 ]
机构
[1] Ohio Univ, Stocker Ctr, Sch Elect Engn & Comp Sci, Athens, OH 45701 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Entropy has been widely used to quantify information for display and examination in determining network status and in detecting anomalies. Although entropy-based methods are effective, they rely on long-term network statistics. Here, we propose an approach that deduces short term observations of network features and their respective time averaged entropies. Acute changes are detected in network feature space and depicted in a visually compact information graph. First, average entropy for each feature is calculated for every second of observation. Then, the resultant short-term information measurement is subjected to first- and second-order time averaging statistics. These time-varying statistics are used as the basis of a novel approach to anomaly estimation based on the well-known Fisher Linear Discriminant (FLD). This process then initiates stochastic clustering to identify the exact time of the security incident or attack on the network. The proposed method is tested on real-tune network traffic data collected from Ohio University's main Internet connection. Experimentation has shown that the presented FLD based method is accurate in identifying anomalies in network feature space. Furthermore, it's performance is highly robust in the presence of bursty network traffic and it is able to detect network anomalies such as BotNet, worm outbreaks, and denial of service attacks.
引用
收藏
页码:219 / 223
页数:5
相关论文
共 50 条
  • [31] Network anomaly detection based on DSOM and ACO clustering
    Feng, Yong
    Zhong, Jiang
    Xiong, Zhong-yang
    Ye, Chun-xiao
    Wu, Kai-gui
    [J]. ADVANCES IN NEURAL NETWORKS - ISNN 2007, PT 2, PROCEEDINGS, 2007, 4492 : 947 - +
  • [32] Infrared Point Target Detection with Fisher Linear Discriminant and Kernel Fisher Linear Discriminant
    Liu, Ruiming
    Zhi, Hongliang
    [J]. JOURNAL OF INFRARED MILLIMETER AND TERAHERTZ WAVES, 2010, 31 (12) : 1491 - 1502
  • [33] Infrared Point Target Detection with Fisher Linear Discriminant and Kernel Fisher Linear Discriminant
    Ruiming Liu
    Hongliang Zhi
    [J]. Journal of Infrared, Millimeter, and Terahertz Waves, 2010, 31 : 1491 - 1502
  • [34] Research on network anomaly detection based on clustering and classifier
    Yang, Hongyu
    Xie, Feng
    Lu, Yi
    [J]. 2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 592 - 597
  • [35] Anomaly detection using visualization and machine learning
    Mizoguchi, F
    [J]. IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 165 - 170
  • [36] Magnetic anomaly detection using entropy filter
    Sheinker, Arie
    Salomonski, Nizan
    Ginzburg, Boris
    Frumkis, Lev
    Kaplan, Ben-Zion
    [J]. MEASUREMENT SCIENCE AND TECHNOLOGY, 2008, 19 (04)
  • [37] Anomaly Detection using Improved Hierarchy Clustering
    Hu Liang
    Ren Wei-wu
    Ren Fei
    [J]. 2009 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COMPUTATIONAL INTELLIGENCE, VOL I, PROCEEDINGS, 2009, : 319 - 323
  • [38] Maritime Anomaly Detection using Density-based Clustering and Recurrent Neural Network
    Zhao, Liangbin
    Shi, Guoyou
    [J]. JOURNAL OF NAVIGATION, 2019, 72 (04): : 894 - 916
  • [39] Network Traffic Anomaly Detection Using Adaptive Density-based Fuzzy Clustering
    Liu, Duo
    Lung, Chung-Horng
    Seddigh, Nabil
    Nandy, Biswajit
    [J]. 2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 823 - 830
  • [40] Unsupervised Anomaly Detection for Network Flow Using Immune Network Based K-means Clustering
    Shi, Yuanquan
    Peng, Xiaoning
    Li, Renfa
    Zhang, Yu
    [J]. DATA SCIENCE, PT 1, 2017, 727 : 386 - 399