A Comparison Between Divergence Measures for Network Anomaly Detection - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue 7th International Conference on Network and Service Management (CNSM 11) Année : 2011

A Comparison Between Divergence Measures for Network Anomaly Detection

Résumé

This paper deals with the detection of flooding attacks which are the most common type of Denial of Service (DoS) attacks. We compare 2 divergence measures (Hellinger distance and Chi-square divergence) to analyze their detection accuracy. The performance of these statistical divergence measures are investigated in terms of true positive and false alarm ratio. A particular focus will be on how to use these measures over Sketch data structure, and which measure provides the best detection accuracy. We conduct performance analysis over publicly available real IP traces (MAWI) collected from the WIDE backbone network. Our experimental results show that Chi-square divergence outperforms Hellinger distance in network anomalies detection.
Fichier principal
Vignette du fichier
CNSM11.pdf (147.86 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00844968 , version 1 (16-07-2013)

Identifiants

  • HAL Id : hal-00844968 , version 1

Citer

Jean Tajer, Ali Makke, Osman Salem, Ahmed Mehaoua. A Comparison Between Divergence Measures for Network Anomaly Detection. 7th International Conference on Network and Service Management (CNSM 11), 2011, pp.1 - 5. ⟨hal-00844968⟩

Collections

LIPADE UP-SCIENCES
70 Consultations
137 Téléchargements

Partager

Gmail Facebook X LinkedIn More