ANOMALY DETECTION IN NETWORK TRAFFIC USING ENTROPY-BASED METHODS: APPLICATION TO VARIOUS TYPES OF CYBERATTACKS

Issues in Information Systems · 2023

This paper proposes an entropy-based approach for detecting anomalies in network traffic.With the exponential growth of data and sophisticated cyberattacks traditional methods struggle to identify evolving attack patterns.To address this, we leverage Shannon and Renyi entropies to analyze network traffic datasets.We are focusing on the entire network traffic.Using a publicly available dataset with labeled traffic samples, we calculate the entropy of different traffic features to assess their effectiveness in anomaly detection and attack identification.The scalability and sensitivity of this approach make it suitable for analyzing diverse and high-volume network data, capturing changes in traffic distributions, and detecting anomalies missed by traditional metrics.The method is easily implementable and interpretable, requiring minimal training data.Our findings show promising results for nine different types of cyberattacks, offering practical insights for robust anomaly detection systems in network security .

Read the paper · More papers on PaperTik