Entropy based Worm and DDoS Attack Detection in Stub networks

Chan‐Kyu Han, Hyoung-Kee Choi · ITC-CSCC :International Technical Conference on Circuits Systems, Computers and Communications · 2007

We present a real-time monitoring system for detecting anomalous network events using the entropy. According to the thermodynamics theory, the entropy accounts for the effects of disorder in the system. When an abnormal factor arises to agitate the current system the entropy must show an abrupt change. In this paper we deliberately model the Internet to measure the entropy. In the model, the Internet is divided into the two networks; one for inside to be protected and the other is for outside where attackers may reside. Packets flowing between these two networks may incur to sustain the current value of the entropy if those packets are in harmony with the system or change abruptly if those agitate the system. In the proposed system we keep track of the value of entropy in time to pinpoint the sudden changes in the value. Those changes are regarded as the installation of attacks in the network. The time-series data of entropy are transformed into the two-dimensional and three-dimensional domains to help visually inspect the activities on the network. We examine the system using network traffic traces containing notorious worms and DoS attacks on the testbed. The result suggests that our approach be able to detect anomalies with the fairly high accuracy. Our contributions are two folds: (1) highly sensitive detection of anomalies and (2) visualization of network activities to alert anomalies.

Read the paper · More papers on PaperTik