TY - GEN
T1 - On-line anomaly detection based on relative entropy
AU - Altaher, Altyeb
AU - Ramadass, Sureswaran
AU - Thuraisingham, Bhavani
AU - Mehedy, Mohammad
PY - 2011
Y1 - 2011
N2 - Because the internet and computer networks are exposed to rapidly increasing number of serious security threats, efficient and effective anomaly detection techniques have become a necessity to secure the internet and computer networks. Traditional signature based anomaly detection techniques failed to detect polymorphic and new security threats. In this paper, we propose an online worm detection system based on relative entropy. The system effectively profiles network traffic features and then uses relative entropy to dynamically determine the traffic changes. It then applies adaptive filter to differentiate the traffic changes and determines whether the traffic is normal or contains worms. Our experimental results show that the proposed system is efficient for on-line anomaly detection, using traffic trace collected in high-speed links.
AB - Because the internet and computer networks are exposed to rapidly increasing number of serious security threats, efficient and effective anomaly detection techniques have become a necessity to secure the internet and computer networks. Traditional signature based anomaly detection techniques failed to detect polymorphic and new security threats. In this paper, we propose an online worm detection system based on relative entropy. The system effectively profiles network traffic features and then uses relative entropy to dynamically determine the traffic changes. It then applies adaptive filter to differentiate the traffic changes and determines whether the traffic is normal or contains worms. Our experimental results show that the proposed system is efficient for on-line anomaly detection, using traffic trace collected in high-speed links.
KW - Network anomaly detection
KW - Network entropy
KW - relative network entropy
UR - http://www.scopus.com/inward/record.url?scp=84858269813&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84858269813&partnerID=8YFLogxK
U2 - 10.1109/ICBNMT.2011.6155890
DO - 10.1109/ICBNMT.2011.6155890
M3 - Conference contribution
AN - SCOPUS:84858269813
SN - 9781612841564
T3 - Proceedings - 2011 4th IEEE International Conference on Broadband Network and Multimedia Technology, IC-BNMT 2011
SP - 33
EP - 36
BT - Proceedings - 2011 4th IEEE International Conference on Broadband Network and Multimedia Technology, IC-BNMT 2011
T2 - 2011 4th IEEE International Conference on Broadband Network and Multimedia Technology, IC-BNMT 2011
Y2 - 28 October 2011 through 30 October 2011
ER -