Network Traffic Anomalies Detecting Using Maximum Entropy Method

<p class="14AbstracttekstasAbstract"><span lang="EN-GB">The problem of traffic anomalies in computer networks is analyzed. NetFlow packets are used as network traffic data and maximum entropy methods is used for anomalies detection. Method detects network anomalies by...

Full description

Bibliographic Details
Main Authors: Dalius Mažeika, Saulius Jasonis
Format: Article
Language:English
Published: Vilnius Gediminas Technical University 2014-05-01
Series:Mokslas: Lietuvos Ateitis
Subjects:
Online Access:http://www.mla.vgtu.lt/index.php/mla/article/view/632
Description
Summary:<p class="14AbstracttekstasAbstract"><span lang="EN-GB">The problem of traffic anomalies in computer networks is analyzed. NetFlow packets are used as network traffic data and maximum entropy methods is used for anomalies detection. Method detects network anomalies by comparing the current network traffic against a baseline distribution. Method is adopted according to NetFow data and performace of the method is improved. Prototype of anomalies detection system was developed and experimental investigation carried out. Results of investigation confirmed that method is sensitive to deviations of the network traffic and can be successfully used for network traffic anomalies detection.</span></p>
ISSN:2029-2341
2029-2252