TADOOP: Mining Network Traffic Anomalies with Hadoop.

Geng Tian,Zhiliang Wang,Xia Yin,Zimu Li,Xingang Shi,Ziyi Lu,Chao Zhou,Yang Yu,Dan Wu
DOI: https://doi.org/10.1007/978-3-319-28865-9_10
2015-01-01
Abstract:Today, various anomalies and large number of flows in a network make traffic anomaly detection a big challenge. In this paper, we propose DTE-FP (Dual qTsallis Entropy for flow Feature with Properties), a more efficient method for traffic anomaly detection. To handle huge amount of traffic, based on Hadoop, we implement a network traffic anomaly detection system named TADOOP, which supports semi-automatic training and both offline and online traffic anomaly detection. TADOOP with a cluster of five servers has been deployed in Tsinghua University Campus Network. Furthermore, we compare DTE-FP with Tsallis entropy, and the experimental results show that DTE-FP has much better detection capability than Tsallis entropy.
What problem does this paper attempt to address?