Detection of Packet Traffic Anomalous Behaviour via Information Entropy

Spatio-temporal dynamics of packet traffic in data networks is complex and its monitoring is a challenging task. We study if information entropy of packet traffic monitored at selected set of nodes may provide a method for monitoring network-wide behaviour of packet traffic and for detection of anomalous traffic, e.g., distributed denial-of-service attacks. We conduct our investigation for a packet switching network model for static and dynamic routings. We show that the proposed information entropy method may detect changes in “natural” randomness of spatio-temporal distributions of packets among routers caused by anomalous traffic and that the emerging anomalies are easier to detect for DDoS attacks with larger number of attackers and/or on networks using static rather than dynamic routing.

[1]  A.T. Lawniczak,et al.  Development and performance of cellular automaton model of OSI network layer of packet-switching networks , 2003, CCECE 2003 - Canadian Conference on Electrical and Computer Engineering. Toward a Caring and Humane Technology (Cat. No.03CH37436).

[2]  Anna T. Lawniczak,et al.  OSI Network‐layer Abstraction: Analysis of Simulation Dynamics and Performance Indicators , 2005 .

[3]  Jian Yuan,et al.  Monitoring the macroscopic effect of DDoS flooding attacks , 2005, IEEE Transactions on Dependable and Secure Computing.

[4]  Alberto Leon-Garcia,et al.  Communication Networks: Fundamental Concepts and Key Architectures , 1999 .

[5]  Antonio Nucci,et al.  Controlled Chaos [Internet Security] , 2007, IEEE Spectrum.

[6]  Ravishankar K. Iyer,et al.  Editorial: State of the Journal Address , 2005, IEEE Trans. Dependable Secur. Comput..

[7]  Anna T. Lawniczak,et al.  Netzwerk: migration of a packet-switching network simulation environment from MS Windows PC to Linux PC and to HPC , 2005, 19th International Symposium on High Performance Computing Systems and Applications (HPCS'05).

[8]  Andrew Adamatzky,et al.  Automata-2008: Theory and Applications of Cellular Automata , 2008 .

[9]  A.T. Lawniczak,et al.  Building blocks of a simulation environment of the OSI network layer of packet-switching networks , 2003, CCECE 2003 - Canadian Conference on Electrical and Computer Engineering. Toward a Caring and Humane Technology (Cat. No.03CH37436).