학술논문

Network anomaly detection using nonextensive entropy
Document Type
Periodical
Source
IEEE Communications Letters IEEE Commun. Lett. Communications Letters, IEEE. 11(12):1034-1036 Dec, 2007
Subject
Communication, Networking and Broadcast Technologies
Entropy
Telecommunication traffic
Computer crime
Computer networks
Routing protocols
Distributed computing
Probability distribution
Proposals
Detectors
Airports
Language
ISSN
1089-7798
1558-2558
2373-7891
Abstract
Detection is a crucial step towards efficiently diagnosing network traffic anomalies within an autonomous system (AS). We propose the adoption of nonextensive entropy - a one-parameter generalization of Shannon entropy - to detect anomalies in network traffic within an AS. Experimental results show that our approach based on nonextensive entropy outperforms previous ones based on classical entropy while providing enhanced flexibility, which is enabled by the possibility of fine-tuning the sensitivity of the detection mechanism.