Network Anomaly Detection by IP Flow Graph Analysis: A DDoS Attack Case Study

Alexandre Aguiar Amaral, Leonardo de Souza Mendes, Eduardo H. M. Pena, Bruno Bogaz Zarpel�ão, Mário Lemes Proença · 2013

This paper introduces a novel approach for anomaly detection. The solution consists of an automatic detection system that operates without the need of network administrator intervention. Network IP flows are modeled by a graph and Tsallis entropy is applied in order to detect anomalies. Furthermore, our solution can extract and present detailed information from the network traffic. It provides to the network administrator a wide view of the damages that network anomalies cause. In order to evaluate the effectiveness of the proposed solution, it was used real data collected from a DDoS attack.

Read the paper · More papers on PaperTik