{"title":"Detection of anomalous packet traffic via entropy","authors":"A. Lawniczak, Hao Wu, B. D. Stefano","doi":"10.1109/CCECE.2009.5090107","DOIUrl":null,"url":null,"abstract":"We study if information entropy of packet traffic passing through selected set of routers may detect anomalous packet traffic (e.g., distributed denial-of-service (DDoS) attacks) in a packet switching network (PSN) model. Given a certain PSN model setup (i.e., topology, routing algorithm, and source load value) a “natural” entropy profile of normal packet traffic monitored at selected routers characterizes normal operation of PSN model. When entropy of packet traffic deviates significantly from this “natural” profile it means that some anomaly in packet traffic emerges. Our simulations of ping DDoS attacks show that after start of attacks the entropy of packet traffics monitored network-wide at relatively small sets of routers may significantly drop and that it is easier to detect these drops if static routing is used instead of dynamic routing. Thus, for detection of DDoS attacks and other anomalous packet traffic information entropy of packet traffic monitored network-wide at properly selected routers can be a useful tool.","PeriodicalId":153464,"journal":{"name":"2009 Canadian Conference on Electrical and Computer Engineering","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-05-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 Canadian Conference on Electrical and Computer Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CCECE.2009.5090107","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
We study if information entropy of packet traffic passing through selected set of routers may detect anomalous packet traffic (e.g., distributed denial-of-service (DDoS) attacks) in a packet switching network (PSN) model. Given a certain PSN model setup (i.e., topology, routing algorithm, and source load value) a “natural” entropy profile of normal packet traffic monitored at selected routers characterizes normal operation of PSN model. When entropy of packet traffic deviates significantly from this “natural” profile it means that some anomaly in packet traffic emerges. Our simulations of ping DDoS attacks show that after start of attacks the entropy of packet traffics monitored network-wide at relatively small sets of routers may significantly drop and that it is easier to detect these drops if static routing is used instead of dynamic routing. Thus, for detection of DDoS attacks and other anomalous packet traffic information entropy of packet traffic monitored network-wide at properly selected routers can be a useful tool.