Network Event Detection with T-Entropy

R. Eimann, Ulrich Speidel, N Brownlee, Yang Jia · ResearchSpace (University of Auckland) · 2005

This paper describes an entropy-based approach for the detection of network events. This is achieved by first converting a stream of network packets into a string and then computing its approximate average entropy rate using a computable complexity measure. Changes in the average entropy rate are interpreted as events. The computational complexity of the presented approach is nearly linear which makes this technique suitable for online scenarios. We present the results of several measurements on actual network data and show that it is indeed possible to associate actual network events with changes in entropy.

Read the paper · More papers on PaperTik