Szczegóły publikacji
Opis bibliograficzny
Network anomaly detection using parameterized entropy / Przemysław Brzeziński, Marcin SZPYRKA, Bartosz Jasiul, Michał Mazur // W: Computer Information Systems and Industrial Management : 13th IFIP TC8 international conference, CISIM 2014 : Ho Chi Minh City, Vietnam, November 5–7, 2014 : proceedings / eds. Khalid Saaed, Václav Snášel. — Berlin ; Heidelberg : Springer, cop. 2014. — (Lecture Notes in Computer Science ; ISSN 0302-9743 ; 8838). — ISBN: 978-3-662-45236-3; e-ISBN: 978-3-662-45237-0. — S. 465–478. — Bibliogr. s. 478. — W bazie Web of Science brak afiliacji AGH
Autorzy (4)
- Bereziński Przemysław
- AGHSzpyrka Marcin
- Jasiul Bartosz
- Mazur Michał
Słowa kluczowe
Dane bibliometryczne
| ID BaDAP | 85612 |
|---|---|
| Data dodania do BaDAP | 2014-11-12 |
| DOI | 10.1007/978-3-662-45237-0_43 |
| Rok publikacji | 2014 |
| Typ publikacji | materiały konferencyjne (aut.) |
| Otwarty dostęp | |
| Konferencja | International Conference on Computer Information Systems and Industrial Management Applications 2014 |
| Czasopismo/seria | Lecture Notes in Computer Science |
Abstract
Entropy-based anomaly detection has recently been extensively studied in order to overcome weaknesses of traditional volume and rule based approaches to network flows analysis. From many entropy measures only Shannon, Titchener and parameterized Renyi and Tsallis entropies have been applied to network anomaly detection. In the paper, our method based on parameterized entropy and supervised learning is presented. With this method we are able to detect a broad spectrum of anomalies with low false positive rate. In addition, we provide information revealing the anomaly type. The experimental results suggest that our method performs better than Shannon-based and volume-based approach.