Detecting anomalies in network traffic using maximum entropy estimation
Explore this paper's citation graph
Summary
A behavior-based anomaly detection method that detects network anomalies by comparing the current network traffic against a baseline distribution with a measure related to the relative entropy of the network traffic under observation with respect to the baseline distribution is developed.
- Type
- article
- Published
- 2005-10-19
- Cited by
- 431
- References
- 15
- OpenAlex
- https://openalex.org/W4239856175
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:9897393
Keywords
Computer science, Principle of maximum entropy, Entropy estimation, Entropy (arrow of time), Artificial intelligence
References
- Bro: a system for detecting network intruders in real-time
- Practical automated detection of stealthy portscans
- Information-theoretic measures for anomaly detection
- A Comparison of Algorithms for Maximum Entropy Parameter Estimation
- A signal analysis of network traffic anomalies
- Detecting SYN flooding attacks
- Aberrant Behavior Detection in Time Series for Network Monitoring
- Anomaly detection in IP networks
- Inducing Features of Random Fields
- A signal analysis of network traffic anomalies
- Efficiently Inducing Features of Conditional Random Fields
Cited by
- Network traffic sampling for improved signature and anomaly based intrusion detection
- A Neural Network Approach to Border Gateway Protocol Peer Failure Detection and Prediction
- Design and Implementation of Parallel Anomaly Detection
- Improving the Evaluation of Network Anomaly Detection Using a DataFusion Approach
- Study of FPGA implementation of entropy norm computation for IP data streams
- Design of the host guard firewall for network protection
- Black Box Anomaly Detection: Is It Utopian?
- New Methods for Network Traffic Anomaly Detection
- Wavelet-based Detection of DoS Attacks.
- Fault Detection and Network Security in Software-Defined Networks with OpenFlow
- Detection of Low-Rate DoS Attacks againstHTTP Servers using Spectral Analysis
- Mesures et Caractérisation du Trafic dans le Réseau National Universitaire (RNU)
- Contribution to the improvement of the performance of wireless mesh networks providing real time services
- Advanced attack tree based intrusion detection
- Destination Address Entropy based Detection and Traceback Approach against Distributed Denial of Service Attacks
- Anomaly Extraction Using Improved FP-Growth Algorithm Based on Compound Single Linked List
- Anomaly detection and response approach based on mapping requests
- A wavelet-based anomaly detection for outbound network traffic
- Mapping the File Systems Genome: rationales, technique, results and applications
- Detection, Classification and Visualization of Anomalies using Generalized Entropy Metrics
Related papers
- A New Method of the Automatically Marked Chinese Part of Speech Based on Gaussian Prior Smoothing Maximum Entropy Model
- An entropy measure for power estimation of Boolean functions
- Estimation of Maximum-Entropy Distribution Based on Genetic Algorithms in Evaluation of the Measurement Uncertainty
- k-NN based bypass entropy and mutual information estimation for incremental remote-sensing image compressibility evaluation
- A client-entropy measure for On-line Signatures
- Product of spacing estimation of entropy for inverse Weibull distribution under progressive type-II censored data with applications
- Image identification and estimation using the maximum entropy principle
- Research on Network Traffic Feature Map Generation and Evaluation Methods
- Efficiency, power, and entropy in event-related fMRI with multiple trial types: Part II: design of experiments