An Entropy-based Method for Attack Detection in Large Scale Network

被引:0
|
作者
Liu, T. [1 ,2 ]
Wang, Z. [2 ]
Wang, H. [2 ]
Lu, K. [2 ]
机构
[1] Xi An Jiao Tong Univ, SKLMS Lab, Xian 710049, Shaanxi, Peoples R China
[2] Xi An Jiao Tong Univ, MOE KLNNIS Lab, Xian 710049, Shaanxi, Peoples R China
关键词
Network Security; Entropy-based; IDS; Shannon Entropy; Renyi Cross Entropy;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection System (IDS) typically generates a huge number of alerts with high false rate, especially in the large scale network, which result in a huge challenge on the efficiency and accuracy of the network attack detection. In this paper, an entropy-based method is proposed to analyze the numerous IDS alerts and detect real network attacks. We use Shannon entropy to examine the distribution of the source IF address, destination IP address, source threat and destination threat and datagram length of IDS alerts; employ Renyi cross entropy to fuse the Shannon entropy vector to detect network attack. In the experiment, we deploy the Snort to monitor part of Xi'an Jiaotong University (XJTU) campus network including 32 C-class network (more than 4000 users), and gather more than 40,000 alerts per hour on average. The entropy-based method is employed to analyze those alerts and detect network attacks. The experiment result shows that our method can detect 96% attacks with very low false alert rate.
引用
收藏
页码:509 / 517
页数:9
相关论文
共 50 条
  • [1] Entropy-Based Profiling of Network Traffic for Detection of Security Attack
    Lee, Tsern-Huei
    He, Jyun-De
    TENCON 2009 - 2009 IEEE REGION 10 CONFERENCE, VOLS 1-4, 2009, : 2505 - 2509
  • [2] An Entropy-Based Network Anomaly Detection Method
    Berezinski, Przemyslaw
    Jasiul, Bartosz
    Szpyrka, Marcin
    ENTROPY, 2015, 17 (04) : 2367 - 2408
  • [3] Entropy-Based Anomaly Detection in a Network
    Ajay Shankar Shukla
    Rohit Maurya
    Wireless Personal Communications, 2018, 99 : 1487 - 1501
  • [4] Entropy-based Network Anomaly Detection
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    2017 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016, : 334 - 340
  • [5] Entropy-Based Anomaly Detection in a Network
    Shukla, Ajay Shankar
    Maurya, Rohit
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (04) : 1487 - 1501
  • [6] Web Attack Detection using Entropy-based Analysis
    Threepak, T.
    Watcharapupong, A.
    2014 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2014), 2014, : 244 - 247
  • [7] An Entropy-based TextWatermarking Detection Method
    Lu, Yijian
    Liu, Aiwei
    Yu, Dianzhi
    Li, Jingjing
    King, Irwin
    PROCEEDINGS OF THE 62ND ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, VOL 1: LONG PAPERS, 2024, : 11724 - 11735
  • [8] An Efficient Entropy-based Network Anomaly Detection Method Using MIB
    Zhao, Lei
    Wang, Fu
    PROCEEDINGS OF 2014 IEEE INTERNATIONAL CONFERENCE ON PROGRESS IN INFORMATICS AND COMPUTING (PIC), 2014, : 428 - 432
  • [9] DDoS attack detection in SDN: Enhancing entropy-based detection with machine learning
    Santos-Neto, Marcos J.
    Bordim, Jacir L.
    Alchieri, Eduardo A. P.
    Ishikawa, Edison
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (11):
  • [10] Entropy-based electricity theft detection in AMI network
    Singh, Sandeep Kumar
    Bose, Ranjan
    Joshi, Anupam
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2018, 3 (02) : 99 - 105