Title
Mutual information applied to anomaly detection.
Abstract
Anomaly detection systems play a significant role in protection mechanism against attacks launched on a network. The greatest challenge in designing systems detecting anomalous exploits is defining what to measure. Effective yet simple, Shannon entropy metrics have been successfully used to detect specific types of malicious traffic in a number of commercially available IDS's. We believe that Renyi entropy measures can also adequately describe the characteristics of a network as a whole as well as detect abnormal traces in the observed traffic. In addition, Renyi entropy metrics might boost sensitivity of the methods when disambiguating certain anomalous patterns. In this paper we describe our efforts to understand how Renyi mutual information can be applied to anomaly detection as an offline computation. An initial analysis has been performed to determine how well fast spreading worms (Slammer, Code Red, and Welchia) can be detected using our technique. We use both synthetic and real data audits to illustrate the potentials of our method and provide a tentative explanation of the results.
Year
DOI
Venue
2008
10.1109/JCN.2008.6388332
Journal of Communications and Networks
Keywords
Field
DocType
Entropy,Grippers,Mutual information,IP networks,Delay
Information theory,Anomaly detection,Data mining,Off line,Computer science,Rényi entropy,Real-time computing,Theoretical computer science,Exploit,Mutual information,Entropy (information theory),Computation
Journal
Volume
Issue
ISSN
10
1
1229-2370
Citations 
PageRank 
References 
5
0.41
7
Authors
4
Name
Order
Citations
PageRank
Yuliya Kopylova181.19
Duncan A. Buell2739172.53
Chin-Tser Huang328545.72
Jeff Janies4918.24