Network Anomaly Detection Using Random Forests and Entropy of Traffic Features

被引:13
|
作者
Yao, Dong [1 ]
Yin, Meijuan [1 ]
Luo, Junyong [1 ]
Zhang, Silong [1 ]
机构
[1] Zhengzhou Informat Sci & Technol Inst, Zhengzhou 450002, Henan, Peoples R China
关键词
anomaly detection; entropy; Random Forests;
D O I
10.1109/MINES.2012.146
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Tracking changes in traffic feature distributions and using it to classify traffic with different behavior is very important in the domain of network anomaly detection. Shannon entropy can be used to find changes in the normal distribution of network traffic to identify anomalies. Standardized entropy provides a measure of uniformity and randomicity on the same baseline for vectors or variables in the different sample space. Random Forests is a machine learning classification algorithm. It is best suited for the analysis of complex or distribution-imbalanced data structures embedded in small to moderate data sets. Anomaly traffic always occupied a little proportion of the whole network traffic. So we employed a combination of entropy measure and Random Forests classification to detect anomalies in network traffic. Our results demonstrate that the new technique is great promise in traffic anomaly detection.
引用
收藏
页码:926 / 929
页数:4
相关论文
共 50 条
  • [41] Anomaly Detection Based on Spatio-Temporal and Sparse Features of Network Traffic in VANETs
    Nie, Laisen
    Wang, Huizhi
    Gong, Shimin
    Ning, Zhaolong
    Obaidat, Mohammad S.
    Hsiao, Kuei-Fang
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [42] Anomaly Detection in Network Traffic Using Advanced Machine Learning Techniques
    Ness, Stephanie
    Eswarakrishnan, Vishwanath
    Sridharan, Harish
    Shinde, Varun
    Janapareddy, Naga Venkata Prasad
    Dhanawat, Vineet
    IEEE ACCESS, 2025, 13 : 16133 - 16149
  • [43] A Novel Network Traffic Anomaly Detection Approach Using the Optimal φ-DTW
    Zhan, Peng
    Xu, Haoran
    Luo, Wei
    Li, Xueqing
    PROCEEDINGS OF 2020 IEEE 11TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2020), 2020, : 48 - 51
  • [44] NETWORK TRAFFIC ANOMALY DETECTION USING CLUSTERING TECHNIQUES AND PERFORMANCE COMPARISON
    Liu, Duo
    Lung, Chung-Horng
    Lambadaris, Ioannis
    Seddigh, Nabil
    2013 26TH ANNUAL IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2013, : 345 - 348
  • [45] A Hybrid Technique Using PCA and Wavelets in Network Traffic Anomaly Detection
    Novakov, Stevan
    Lung, Chung-Horng
    Lambadaris, Ioannis
    Seddigh, Nabil
    INTERNATIONAL JOURNAL OF MOBILE COMPUTING AND MULTIMEDIA COMMUNICATIONS, 2014, 6 (01) : 17 - 53
  • [46] Anomaly Detection in Network Traffic using Jensen-Shannon Divergence
    Salem, Osman
    Nait-Abdesselam, Farid
    Mehaoua, Ahmed
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [47] Entropy-Based Anomaly Detection in a Network
    Shukla, Ajay Shankar
    Maurya, Rohit
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (04) : 1487 - 1501
  • [48] Entropy Based Method for Network Anomaly Detection
    Quan, Qian
    Hong-Yi, Che
    Rui, Zhang
    IEEE 15TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2009, : 189 - 191
  • [49] Entropy-based Network Anomaly Detection
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    2017 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016, : 334 - 340
  • [50] Entropy-Based Anomaly Detection in a Network
    Ajay Shankar Shukla
    Rohit Maurya
    Wireless Personal Communications, 2018, 99 : 1487 - 1501