Analysis Method of Multi-Source Flow Characteristics and Its Application in Anomaly Detection

牛国林,管晓宏,龙毅,秦涛
DOI: https://doi.org/10.3969/j.issn.1009-3443.2009.04.009
2009-01-01
Abstract:Based on tradeoffs analysis of abnormal behavior and detection methods,a multi-source traffic features analysis and abnormal detection method was proposed.The distribution characteristics of the flow size,IP addresses and ports were analyzed and found to be efficacious in traffic patterns analysis.The Renyi entropy was employed to fuse the multi-source information captured by different traffic features,and an abnormal behavior detection method was presented.Beacause of using the multi-source information,the models could detect many kinds of abnormal behaviors,which was an impossible mission for many other traditional abnormal detection methods.The experimental results based on actual network data show that the proposed abnormal detection methods are effective in detecting known and unknown attacks with high-accuracy detection rate and low complexity.
What problem does this paper attempt to address?