A Small-time Scale Netflow-based Anomaly Traffic Detecting Method Using MapReduce

Jinsong Wang, Long Zhang, Kai Shi, Hong-hao Zhang · International Journal of Security and Its Applications · 2014

Anomaly traffic detecting using Netflow data is one of important problems in the field of network security. In this paper, we proposed an approach using MapReduce model, which was realized by means of the entropy observation and DFN (Distinct feature number) distribution deviations of traffic features under anomalies at small time scales. The MapReduce was used to deal with huge amounts of data with the aid of computer cluster processing. Experimental results show the effectiveness of the proposed approach.

Read the paper · More papers on PaperTik