Information Theory and Data-Mining Techniques for Network Traffic Profiling for Intrusion Detection
Pablo Velarde-Alvarado, Rafael Martínez-Peláez, Joel Ruiz-Ibarra, Víctor Morales-Rocha · Journal of Computer and Communications · 2014
In this paper, information theory and data mining techniques to extract knowledge of network traffic behavior for packet-level and flow-level are proposed, which can be applied for traffic profiling in intrusion detection systems. The empirical analysis of our profiles through the rate of remaining features at the packet-level, as well as the three-dimensional spaces of entropy at the flow-level, provide a fast detection of intrusions caused by port scanning and worm attacks.