Real-time Anomaly Detection Model for Worm Mails in High-Speed Network

LUO Hao,FANG Bin-xing,YUN Xiao-chun,WANG Xin,XIN Yi
DOI: https://doi.org/10.3321/j.issn:1000-436x.2006.02.006
2006-01-01
Abstract:An Email flow anomaly detection method based on leaky integrate-and-fire model was presented for detecting flow anomaly in the process of mail worm propagation.According to the day period and week period properties of the mail flow,Firstly the Hellinger distance between current mail flow and history statistic was calculated,and then integrate the Hellinger distance with Leaky integrate-and-fire method.In this way,the slice variety of flow was accumulated in the mail worm propagation slow start phase to archive the capability of the anomaly detection before the worm enter the fast spread phase.As this method only checks the mail flow information,it is suitable for high speed network mail flow anomaly detection.
What problem does this paper attempt to address?