A traffic anomaly detection and classification method based on cross entropy is proposed to identify network attack behaviors accurately. Both features of traffic flow header and traffic behavior are used to characterize three types of common attacks
such as DoS attacks
port scans and network scans. The cross entropy is used to measure traffic distribution changes for each traffic feature
and a behavior vector for each attack type is built. Then exponentially weighted moving average control chart method is applied to multiple cross entropy indicators for anomaly detection
and an anomaly vector is generated. The similarity between the anomaly vector and each behavior vector is computed to classify attacks. Experimental results and comparisons with the Shannon entropy measurement on Netflow traffic in a router show that under relatively weaker attacks
the true positive rate
average precision and accuracy of the cross entropy measurement in attack classification rise by 13%
CHEN Guangying, ZHANG Qianli, LI Xing. SVM classification-based intrusion detection system[J]. Journal of China Institute of Communications, 2002, 23(5): 51-56.
KRISHAN K, JOSHIL R C, KULDIP S. A distributed approach using entropy to detect DDoS attacks in ISP domain [C]∥Proceedings of International Conference on Signal Processing, Communications and Networking. Piscataway, NJ, USA: IEEE, 2007:331-337.
ANUKOOL L, MARK C, CHRISTOPHE D. Mining Anomalies using traffic feature distributions [C]∥Proceedings of Special Interest Group on Data Communication Conference. New York,USA: ACM, 2005:217-228.
GEORGE N, VYAS S, DAVID G, et al. An empirical evaluation of entropy-based traffic anomaly detection [C]∥Proceedings of Internet Measurement Conference. New York, USA: ACM, 2008:151-156.
QIN Tao, GUAN Xiaohong, LI Wei, et al. Dynamic features measurement and analysis for large-scale networks [C]∥Proceedings of International Conference on Communications. Piscataway, NJ, USA: IEEE, 2008: 212-216.
YAN Ruoyu, ZHENG Qinhua. Using renyi cross entropy to analyze traffic matrix and detect DDoS attacks [J]. Information Technology Journal, 2009, 8(8):1180-1188.
MONTGOMERY D C, MASTRANGELO C M. Some statistical process control methods for autocorrelated data [J]. Journal of Quality Technology, 1991, 23(3): 179-193.