Generalized Network Temperature for DDoS Detection through Renyi Entropy

被引:1
|
作者
Wang, Xiang [1 ]
Zhang, Xing [1 ]
Wang, Changda [1 ]
机构
[1] Jiangsu Univ, Zhenjiang, Jiangsu, Peoples R China
关键词
network anomaly detection; generalized network temperature; EWMA; SOFTWARE-DEFINED NETWORKING; ATTACKS;
D O I
10.1109/QRS-C57518.2022.00014
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial-of-Services (DDoS) are serious network threats hardly eliminated. Current network entropy-based DDoS detection methods suffer from distinguishing DDoS attack traffic among normal traffic through a fixed empirical detection threshold, i.e., most of such thresholds are case-sensitive ones. With the Renyi entropy of a network, the paper devised a Generalized Network Temperature (GNT) based approach for DDoS attack detection, where GNT is a novel and fine-granular-scale statistical indicator that describes the network entropy changes in the light of both network traffic and network topology changes. Within a series of predefined time windows, our proposed approach first collects the selected network traffic features and then calculates the GNT for each time window. Second, the DDoS attacks are then acknowledged or denied by comparing each GNT to a dynamically adjustable threshold generated by the Exponentially Weighted Moving Average (EWMA) model. Furthermore, the publicly available CIC DoS 2017 dataset is utilized to test the proposed approach in the paper. The experimental results show that our proposed approach outperforms the known Shannon entropy-based DDoS attack detection methods with respect to both efficacy and efficiency.
引用
收藏
页码:24 / 33
页数:10
相关论文
共 50 条
  • [21] Speckle Denoising through Local Renyi Entropy Smoothing
    Gabarda, Salvador
    Cristobal, Gabriel
    COMPUTER ANALYSIS OF IMAGES AND PATTERNS: 14TH INTERNATIONAL CONFERENCE, CAIP 2011, PT 2, 2011, 6855 : 340 - 347
  • [22] Detection of events in biomedical signals by a Renyi entropy measure
    Gabarda, S.
    Cristobal, G.
    Martinez-Alajarin, J.
    Ruiz, R.
    INFORMATION OPTICS, 2006, 860 : 210 - +
  • [23] HUMAN SEIZURE DETECTION USING QUADRATIC RENYI ENTROPY
    Feltane, Amal
    Bartels, G. F. Boudreaux
    Gaitanis, John
    Boudria, Yacine
    Besio, Walter
    2013 6TH INTERNATIONAL IEEE/EMBS CONFERENCE ON NEURAL ENGINEERING (NER), 2013, : 815 - 818
  • [24] Renyi Entropy Based Failure Detection of Medical Electrodes
    Marasovic, Ivan
    Saulig, Nicoletta
    Milanovic, Zeljka
    2015 23RD INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2015, : 346 - 350
  • [25] Detection of Congestive Heart Failure using Renyi Entropy
    Cornforth, David J.
    Jelinek, Herbert F.
    2016 COMPUTING IN CARDIOLOGY CONFERENCE (CINC), VOL 43, 2016, 43 : 669 - 672
  • [26] Characterization of Rossler and Duffing maps with Renyi entropy and generalized complexity measures
    Godo, B.
    Nagy, A.
    IC-MSQUARE 2012: INTERNATIONAL CONFERENCE ON MATHEMATICAL MODELLING IN PHYSICAL SCIENCES, 2013, 410
  • [27] Maximum Renyi entropy principle and the generalized Thomas-Fermi model
    Nagy, A.
    Romera, E.
    PHYSICS LETTERS A, 2009, 373 (8-9) : 844 - 846
  • [28] DDoS Attack Detection Scheme Based on Entropy and PSO-BP Neural Network in SDN
    Liu, Zhenpeng
    He, Yupeng
    Wang, Wensheng
    Zhang, Bin
    CHINA COMMUNICATIONS, 2019, 16 (07) : 144 - 155
  • [29] DDoS Attack Detection Scheme Based on Entropy and PSO-BP Neural Network in SDN
    Zhenpeng Liu
    Yupeng He
    Wensheng Wang
    Bin Zhang
    China Communications, 2019, 16 (07) : 144 - 155
  • [30] Wavelet packet best basis search using generalized Renyi entropy
    Dansereau, RM
    Kinsner, W
    Cevher, V
    IEEE CCEC 2002: CANADIAN CONFERENCE ON ELECTRCIAL AND COMPUTER ENGINEERING, VOLS 1-3, CONFERENCE PROCEEDINGS, 2002, : 1005 - 1008