跳到主要导航 跳到搜索 跳到主要内容

Multi-scale entropy and Renyi cross entropy based traffic anomaly detection

  • Xi'an Jiaotong University
  • Guangdong Ocean University

科研成果: 会议稿件论文同行评审

8 引用 (Scopus)

摘要

The idea of using entropy measurement to detect anomalies is not a novelty in the research community. But all these entropy-based approaches are single-scale based "complexity" methods, and don't consider temporal and spatial correlation in network traffic. In this paper, multi-scale entropy (MSE) and Renyi cross entropy are introduced to solve these problems. First, a kind of Port-to-Port traffic termed IF-flow in router is defined. Internal traffic matrix can be constructed by IF-flows. Then a new scheme based on MSE and Renyi cross entropy is proposed to detect traffic anomaly existed in IF-flow matrix. MSE is used to detect IF-flow traces in time scales. Renyi cross entropy is used to detect anomaly existed in IF-flow matrix in space and small scale time, and pinpoint IF-flow(s) responsible for entropy change. An improved method to calculate Renyi Cross entropy is proposed to reduce false alarm and identify anomaly duration. The experimental results indicate the scheme can detect anomaly accurately in time and space.

源语言英语
554-558
页数5
DOI
出版状态已出版 - 2008
活动2008 11th IEEE Singapore International Conference on Communication Systems, ICCS 2008 - Guangzhou, 中国
期限: 19 11月 200821 11月 2008

会议

会议2008 11th IEEE Singapore International Conference on Communication Systems, ICCS 2008
国家/地区中国
Guangzhou
时期19/11/0821/11/08

学术指纹

探究 'Multi-scale entropy and Renyi cross entropy based traffic anomaly detection' 的科研主题。它们共同构成独一无二的指纹。

引用此