作者: Ziyu Wang , Jiahai Yang , Fuliang Li
DOI: 10.1007/978-3-319-23802-9_10
关键词:
摘要: Network anomalies have been a serious challenge for the Internet nowadays. In this paper, two new metrics, IGTE (Inter-group Traffic Entropy) and IGFE Flow Entropy), are proposed network anomaly detection. It is observed that highly correlated usually change synchronously when no occurs. However, once occur, linear correlation would be destroyed. Based on observation, we propose regression model built upon IGFE, to detect anomalies. We use both CERNET2 netflow data synthetic validate its corresponding detection method. The results show regression-based method works well outperforms known wavelet-based