Network Anomaly Detection Using Random Forests and Entropy of Traffic Features

被引:13
|
作者
Yao, Dong [1 ]
Yin, Meijuan [1 ]
Luo, Junyong [1 ]
Zhang, Silong [1 ]
机构
[1] Zhengzhou Informat Sci & Technol Inst, Zhengzhou 450002, Henan, Peoples R China
关键词
anomaly detection; entropy; Random Forests;
D O I
10.1109/MINES.2012.146
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Tracking changes in traffic feature distributions and using it to classify traffic with different behavior is very important in the domain of network anomaly detection. Shannon entropy can be used to find changes in the normal distribution of network traffic to identify anomalies. Standardized entropy provides a measure of uniformity and randomicity on the same baseline for vectors or variables in the different sample space. Random Forests is a machine learning classification algorithm. It is best suited for the analysis of complex or distribution-imbalanced data structures embedded in small to moderate data sets. Anomaly traffic always occupied a little proportion of the whole network traffic. So we employed a combination of entropy measure and Random Forests classification to detect anomalies in network traffic. Our results demonstrate that the new technique is great promise in traffic anomaly detection.
引用
收藏
页码:926 / 929
页数:4
相关论文
共 50 条
  • [1] Traffic Sign Detection and Recognition using Features Combination and Random Forests
    Ellahyani, Ayoub
    El Ansari, Mohamed
    El Jaafari, Ilyas
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (01) : 686 - 693
  • [2] Analysis of network traffic features for anomaly detection
    Iglesias, Felix
    Zseby, Tanja
    MACHINE LEARNING, 2015, 101 (1-3) : 59 - 84
  • [3] Analysis of network traffic features for anomaly detection
    Félix Iglesias
    Tanja Zseby
    Machine Learning, 2015, 101 : 59 - 84
  • [4] Adjustable Piecewise Entropy for Network Traffic Anomaly Detection
    Tian, Geng
    Wang, Zhiliang
    Yin, Xia
    Li, Zimu
    Shi, Xingang
    Lu, Ziyi
    Zhou, Chao
    Guo, Yingya
    2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2015, : 59 - 60
  • [5] Network backbone anomaly detection using double random forests based on non-extensive entropy feature extraction
    Yin, Meijuan
    Yao, Dong
    Luo, Junyong
    Liu, Xiaonan
    Ma, Jing
    2013 NINTH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION (ICNC), 2013, : 80 - 84
  • [6] Using random forests for network-based anomaly detection at active routers
    Prashanth, G.
    Prashanth, V.
    Jayashree, P.
    Srinivasan, N.
    ICSCN 2008: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING COMMUNICATIONS AND NETWORKING, 2008, : 93 - 96
  • [7] Network Traffic Anomaly Detection Based on Maximum Entropy Model
    Qian Yaguan
    Wu Chunming
    Yang Qiang
    Wang Bin
    CHINESE JOURNAL OF ELECTRONICS, 2012, 21 (03): : 579 - 582
  • [8] Network anomaly detection using nonextensive entropy
    Ziviani, Artur
    Gomes, Antonio Tadeu A.
    Monsores, Marcelo L.
    Rodrigues, Paulo S. S.
    IEEE COMMUNICATIONS LETTERS, 2007, 11 (12) : 1034 - 1036
  • [9] Network Anomaly Detection Using Parameterized Entropy
    Berezinski, Przemyslaw
    Szpyrka, Marcin
    Jasiul, Bartosz
    Mazur, Michal
    COMPUTER INFORMATION SYSTEMS AND INDUSTRIAL MANAGEMENT, CISIM 2014, 2014, 8838 : 465 - 478
  • [10] Small Defect Detection Using Convolutional Neural Network Features and Random Forests
    Dong, Xinghui
    Taylor, Chris J.
    Cootes, Tim F.
    COMPUTER VISION - ECCV 2018 WORKSHOPS, PT IV, 2019, 11132 : 398 - 412