首页期刊简介编委会征稿启事出版道德声明审稿流程读者订阅论文查重联系我们English
引用本文
  • 易胜蓝.利用互信息进行网络异常检测的熵特征优选[J].电讯技术,2012,52(6): - .    [点击复制]
  • YI Sheng-lan.Entropy feature selection of network anomaly detection by using mutual information[J].,2012,52(6): - .   [点击复制]
【打印本页】 【下载PDF全文】 查看/发表评论下载PDF阅读器关闭

←前一篇|后一篇→

过刊浏览    高级检索

本文已被:浏览 1710次   下载 1471 本文二维码信息
码上扫一扫!
利用互信息进行网络异常检测的熵特征优选
易胜蓝
0
(中国西南电子技术研究所,成都 610036)
摘要:
首先讨论了传统流量统计分析的缺点,指出熵分析能够反映更多潜在的信息,发现传 统流量统计分析不能发现的网络异常。其次,讨论了流量熵和计数熵的不同,指出两者应该 配合使用,不能如现有研究中一样片面地使用其中一种。最后,用互信息法分析了两种熵的 常用特征,实验发现两者分别呈现冗余状态,在剔除冗余之后检测的效率有明显提高,且不 失检测准确率。
关键词:  网络异常检测  网络流量  互信息  熵特征优选
DOI:
基金项目:
Entropy feature selection of network anomaly detection by using mutual information
YI Sheng-lan
()
Abstract:
Firstly, the shortcomings of traditional statistic al analysis using network flow data are discussed, and it is pointed out that th e entropy analysis ca n reflect more potential information to find out more network anomaly that can n ot be found by the traditional statistical analysis. Secondly, the difference be tween the flow entropy and count entropy is discussed and it is proposed that th ey should be used cooperatively and that using one of them just as existing stud ies is not recommended. Finally, features of the two kinds of entropy are studie d bymutual information analysis. The simulations show that there is redundant in them. After redundant features are eliminated, the detection efficiency is incr eased significantly while the detection accuracy is maintained.
Key words:  network anomaly detection  network traffic  mutual information  entropy feature sel ection
安全联盟站长平台