Network Anomaly Detection Using Random Forests and Entropy of Traffic Features

被引:13
|
作者
Yao, Dong [1 ]
Yin, Meijuan [1 ]
Luo, Junyong [1 ]
Zhang, Silong [1 ]
机构
[1] Zhengzhou Informat Sci & Technol Inst, Zhengzhou 450002, Henan, Peoples R China
关键词
anomaly detection; entropy; Random Forests;
D O I
10.1109/MINES.2012.146
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Tracking changes in traffic feature distributions and using it to classify traffic with different behavior is very important in the domain of network anomaly detection. Shannon entropy can be used to find changes in the normal distribution of network traffic to identify anomalies. Standardized entropy provides a measure of uniformity and randomicity on the same baseline for vectors or variables in the different sample space. Random Forests is a machine learning classification algorithm. It is best suited for the analysis of complex or distribution-imbalanced data structures embedded in small to moderate data sets. Anomaly traffic always occupied a little proportion of the whole network traffic. So we employed a combination of entropy measure and Random Forests classification to detect anomalies in network traffic. Our results demonstrate that the new technique is great promise in traffic anomaly detection.
引用
收藏
页码:926 / 929
页数:4
相关论文
共 50 条
  • [31] Anomaly detection for network traffic flow
    Shan, Rongsheng
    Li, Jianhua
    Wang, Mingzheng
    Journal of Southeast University (English Edition), 2004, 20 (01) : 16 - 20
  • [32] ENTVis: A Visual Analytic Tool for Entropy-Based Network Traffic Anomaly Detection
    Zhou, Fangfang
    Huang, Wei
    Zhao, Ying
    Shi, Yang
    Liang, Xing
    Fan, Xiaoping
    IEEE COMPUTER GRAPHICS AND APPLICATIONS, 2015, 35 (06) : 42 - 50
  • [33] A hybrid network intrusion detection technique using random forests
    Zhang, Jiong
    Zulkernine, Mohammad
    FIRST INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2006, : 262 - +
  • [34] Fingerprint Liveness Detection Using Multiple Static Features and Random Forests
    Guo, Yanyan
    Fei, Xiangdong
    Zhao, Qijun
    INTERNATIONAL JOURNAL OF IMAGE AND GRAPHICS, 2014, 14 (04)
  • [35] Anomaly Detection and Visualization using Fisher Discriminant Clustering of Network Entropy
    Celenk, Mehmet
    Conley, Thomas
    Willis, John
    Graham, James
    2008 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION MANAGEMENT, VOLS 1 AND 2, 2008, : 219 - 223
  • [36] Design and Implementation of an Anomaly Network Traffic Detection Model Integrating Temporal and Spatial Features
    Li, Ming
    Han, Dezhi
    Yin, Xinming
    Liu, Han
    Li, Dun
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [37] Anomaly Detection for PTM's Network Traffic Using Association Rule
    Eljadi, Entisar E.
    Othman, Zulaiha Ali
    2011 3RD CONFERENCE ON DATA MINING AND OPTIMIZATION (DMO), 2011, : 63 - 69
  • [38] Anomaly detection in network traffic using Jensen-Shannon divergence
    LIPADE Laboratory, University Paris Descartes, France
    不详
    IEEE Int Conf Commun, 2012, (5200-5204):
  • [39] Anomaly Detection Based on Spatio-Temporal and Sparse Features of Network Traffic in VANETs
    Nie, Laisen
    Wu, Yixuan
    Wang, Huizhi
    Li, Yongkang
    IEEE ACCESS, 2019, 7 : 177954 - 177964
  • [40] Anomaly Detection in Network Traffic using K-mean clustering
    Kumari, R.
    Sheetanshu
    Singh, M. K.
    Jha, R.
    Singh, N. K.
    2016 3RD INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN INFORMATION TECHNOLOGY (RAIT), 2016, : 372 - 378