A method to detect network attacks using entropy is proposed to solve the problem that the existing intrusion detection system(IDS)typically generates large amounts of alerts with high false rate. Rainey cross entropy is employed to fuse the Shannon entropy vector for five properties of alerts. These five properties are source IP address
destination IP address
source threat
target threat and datagram length. Then the fusing result is used to describe the network state
and is compared with the normal network state to identify the anomalies. The experimental results on actual network attacks data and synthetic attacks show that the proposed approach can detect network attacks with a hit rate more than 90% whereas the false rate is less 1%. Comparisons with the attack detection method based on the characteristics of the Shannon entropy show that the proposed method is more sensitive to attacks
and is easier to detect in the order Denial of Service(DoS)and hosts intrude attacks
and then the hosts scan and port scan attacks
however
is relatively difficult to worm attacks. The test results also show that the proposed method is better than the compared systems with higher hit rate and lower false positives.
关键词
Keywords
references
SCARFONE K, MELL P. Guide to intrusion detection and prevention systems [M]. Gaithersburg, MD, USA: NIST Special Publication, 2007: 9.
TJHAI G, PAPADAKI M, FURNELL S, et al. The problem of false alarms: evaluation with snort and DARPA 1999 dataset [C]∥Proceedings of 5th International Conference on Trust, Privacy and Security in Digital Business. Berlin, Germany: Springer-Verlag, 2008: 139-150.
ABIMBOLA A A, MUNOZ J M, BUCHANAN W J. Investigating false positive reduction in http via procedure analysis [C]∥Proceeding of the International Conference on Networking and Services. Los Alamitos, CA, USA: IEEE Computer Society, 2006: 87-93.
TIAN Zhihong, ZHANG Weizhe, YE Jianwei, et al. Reduction of false positives in intrusion detection via adaptive alert classifier [C]∥International Conference on Information and Automation. Piscataway, NJ USA: IEEE, 2008: 1599-1602.
ALSHAMMARI R, SONAMTHIANG S, TEIMOURI M, et al. Using neuro-fuzzy approach to reduce false positive alerts [C]∥Proceeding of the Fifth Annual Conference on Communication Networks and Services Research. Los Alamitos, CA, USA: IEEE Computer Society, 2007: 345-349.
SPATHOULAS G P, KATSIKAS S K. Reducing false positives in intrusion detection systems [J]. Computers Security, 2010, 29(1): 35-44
GUO Zhenbing, QIU Zhengding. Identification of BitTorrent traffic for high speed network using packet sampling and application signatures [J]. Journal of Computer Research and Development, 2008, 45(2): 227-236.
NIU Guolin, GUAN Xiaohong, LONG Yi, et al, Analysis method of multi-source flow characteristics and its application in anomaly detection [J]. Journal of PLA University of Science and Technology: Nature Science Edition, 2009, 10(4): 350-355.
NYCHIS G, SEKAR V, ANDERSEN D G, et al. An empirical evaluation of entropy-based traffic anomaly detection [C]∥Proceedings of the 8th ACM SIGCOMM Internet Measurement Conference. New York, USA: ACM, 2008: 151-156.