Effect of nonstationarity of network traffic in entropy-based intrusion detection (case study).

Autor: Basicevic, Ilija, Kostovic, Zarko, Popovic, Miroslav, Ocovaj, Stanislav
Zdroj: 2013 21st Telecommunications Forum Telfor (TELFOR); 2013, p125-128, 4p
Abstrakt: Anomaly-based network intrusion detection that uses entropy has been researched for quite some time. In this paper, we present results of application of an entropy-based anomaly detector, implemented as an extension of snort intrusion detection system. The detector has been realized as a platform for case study on applicability of entropy-based techniques in network intrusion detection. The paper presents results of the detector's application to two available network traces. The analysis of results shows that nonstationarity is an important property of network traffic which has to be taken into account in entropy based intrusion detection. [ABSTRACT FROM PUBLISHER]
Databáze: Complementary Index