Entropy-Based Characterization of Internet Background Radiation

نویسندگان

  • Félix Iglesias
  • Tanja Zseby
چکیده

Network security requires real-time monitoring of network traffic in order to detect new and unexpected attacks. Attack detection methods based on deep packet inspection are time consuming and costly, due to their high computational demands. This paper proposes a fast, lightweight method to distinguish different attack types observed in an IP darkspace monitor. The method is based on entropy measures of traffic-flow features and machine learning techniques. The explored data belongs to a portion of the Internet background radiation from a large IP darkspace, i.e., real traffic captures that exclusively contain unsolicited traffic, ongoing attacks, attack preparation activities and attack aftermaths. Results from an in-depth traffic analysis based on packet headers and content are used as a reference to label data and to evaluate the quality of the entropy-based classification. Full IP darkspace traffic captures from a three-week observation period in April, 2012, are used to compare the entropy-based classification with the in-depth traffic analysis. Results show that several traffic types present a high correlation to the respective traffic-flow entropy signals and can even fit polynomial regression models. Therefore, sudden changes in traffic types caused by new attacks or attack preparation activities can be identified based on entropy variations.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Influence of inclined Lorentz forces on entropy generation analysis for viscoelastic fluid over a stretching sheet with nonlinear thermal radiation and heat source/sink

In the present study, an analytical investigation on the entropy generation examination for viscoelastic fluid flow involving inclined magnetic field and non-linear thermal radiation aspects with the heat source and sink over a stretching sheet has been done. The boundary layer governing partial differential equations were converted in terms of appropriate similarity transformations to non-line...

متن کامل

Entropy Properties of Certain Record Statistics and Some Characterization Results

In this paper, the largest and the smallest observations are considered, at the time when a new record of either kind (upper or lower) occurs based on a sequence of independent random variables with identical continuous distributions. We prove that sequences of the residual or past entropy of the current records characterizes F in the family of continuous distributions. The exponential and the ...

متن کامل

Some Results Based on Entropy Properties of Progressive Type-II Censored Data

In many life-testing and reliability studies, the experimenter might not always obtain complete information on failure times for all experimental units. One of the most common censoring schemes is progressive type-II censoring. The aim of this paper is characterizing the parent distributions based on Shannon entropy of progressive type-II censored order statistics. It is shown that the equality...

متن کامل

Investigation of the Slipping Wear based on the Rate of Entropy Generation

Wear is a complicated phenomenon caused by the relative movement of two contacting surfaces compressed together by a normal force. Prediction of the wear, in most cases, requires various experiments and microstructural characterization of the contacting surfaces. Mathematical models based on physical concepts could provide considerable help in understanding the physical behavior and hence the p...

متن کامل

Investigation of the Slipping Wear based on the Rate of Entropy Generation

Wear is a complicated phenomenon caused by the relative movement of two contacting surfaces compressed together by a normal force. Prediction of the wear, in most cases, requires various experiments and microstructural characterization of the contacting surfaces. Mathematical models based on physical concepts could provide considerable help in understanding the physical behavior and hence the p...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Entropy

دوره 17  شماره 

صفحات  -

تاریخ انتشار 2015