Entropy Based Method for Network Anomaly Detection

Q. Qian,Hongyi Che,Rui Zhang
DOI: https://doi.org/10.1109/PRDC.2009.38
2009-01-01
Abstract:Entropy based intrusion detection which recognizes the network behavior only depends on the packets themselves and do not need any security background knowledge or user interventions, shows great appealing in network security areas. In this paper, we compare two entropy methods, network entropy and normalized relative network entropy(NRNE), to classify different network behaviors. The experimental results show although the two methods are efficient, the improved relative network entropy, NRNE is better which takes more attributes into consideration simultaneously and we can get an overall view of the abnormal network behavior. Keywords-Network entropy;Normalized relative network entropy;Network intrusion detection
Computer Science
What problem does this paper attempt to address?