English
Related papers

Related papers: Characterising Payload Entropy in Packet Flows

200 papers

DNS tunneling techniques are often used for malicious purposes but network security mechanisms have struggled to detect these. Network forensic analysis has thus been used but has proved slow and effort intensive as Network Forensics…

Cryptography and Security · Computer Science 2017-09-20 Irvin Homem , Panagiotis Papapetrou , Spyridon Dosis

Identifying threats in a network traffic flow which is encrypted is uniquely challenging. On one hand it is extremely difficult to simply decrypt the traffic due to modern encryption algorithms. On the other hand, passing such an encrypted…

Cryptography and Security · Computer Science 2020-11-10 Syed Muhammad Kumail Raza , Juan Caballero

We characterize different cell states, related to cancer and ageing phenotypes, by a measure of entropy of network ensembles, integrating gene expression values and protein interaction networks. The entropy measure estimates the parameter…

Molecular Networks · Quantitative Biology 2013-05-24 G. Menichetti , G. Bianconi , E. Giampieri , G. Castellani , D. Remondini

Hacking and false data injection from adversaries can threaten power grids' everyday operations and cause significant economic loss. Anomaly detection in power grids aims to detect and discriminate anomalies caused by cyber attacks against…

Machine Learning · Computer Science 2023-03-14 Xijuan Sun , Di Wu , Arnaud Zinflou , Benoit Boulet

The unsupervised detection of anomalies in time series data has important applications in user behavioral modeling, fraud detection, and cybersecurity. Anomaly detection has, in fact, been extensively studied in categorical sequences.…

Social and Information Networks · Computer Science 2021-02-24 Timothy LaRock , Vahan Nanumyan , Ingo Scholtes , Giona Casiraghi , Tina Eliassi-Rad , Frank Schweitzer

This paper aims to identify the operational region of a link in terms of its utilization and alert operators at the point where the link becomes overloaded and requires a capacity upgrade. The number of active flows is considered the real…

Networking and Internet Architecture · Computer Science 2009-11-16 A. M. Sukhov , D. I. Sidelnikov , A. Galtsev , A. P. Platonov , M. V. Strizhov

The entropy of a hierarchical network topology in an ensemble of sparse random networks with "hidden variables" associated to its nodes, is the log-likelihood that a given network topology is present in the chosen ensemble.We obtain a…

Disordered Systems and Neural Networks · Physics 2009-11-13 Ginestra Bianconi , Anthony C. C. Coolen , Conrad J. Perez Vicente

While several techniques for detecting trace-level anomalies in event logs in offline settings have appeared recently in the literature, such techniques are currently lacking for online settings. Event log anomaly detection in online…

Machine Learning · Computer Science 2021-03-02 Jonghyeon Ko , Marco Comuzzi

Dynamic networks, also called network streams, are an important data representation that applies to many real-world domains. Many sets of network data such as e-mail networks, social networks, or internet traffic networks are best…

Social and Information Networks · Computer Science 2014-11-17 Timothy La Fond , Jennifer Neville , Brian Gallagher

Until two decades ago, industrial networks were deemed secure due to physical separation from public networks. An abundance of successful attacks proved that assumption wrong. Intrusion detection solutions for industrial application need to…

Cryptography and Security · Computer Science 2019-07-10 Simon D. Duque Anton , Daniel Fraunholz , Hans Dieter Schotten

The sharing of network traces is an important prerequisite for the development and evaluation of efficient anomaly detection mechanisms. Unfortunately, privacy concerns and data protection laws prevent network operators from sharing these…

Networking and Internet Architecture · Computer Science 2008-10-10 Martin Burkhart , Daniela Brauckhoff , Martin May

Information flow analysis has largely ignored the setting where the analyst has neither control over nor a complete model of the analyzed system. We formalize such limited information flow analyses and study an instance of it: detecting the…

Cryptography and Security · Computer Science 2014-05-13 Michael Carl Tschantz , Amit Datta , Anupam Datta , Jeannette M. Wing

Graph based entropy, an index of the diversity of events in their distribution to parts of a co-occurrence graph, is proposed for detecting signs of structural changes in the data that are informative in explaining latent dynamics of…

Social and Information Networks · Computer Science 2019-05-03 Yukio Ohsawa

Many organisations manage service quality and monitor a large set devices and servers where each entity is associated with telemetry or physical sensor data series. Recently, various methods have been proposed to detect behavioural…

Social and Information Networks · Computer Science 2023-05-10 Len Feremans , Boris Cule , Bart Goethals

Distributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is…

Networking and Internet Architecture · Computer Science 2021-11-05 Damu Ding , Marco Savi , Domenico Siracusa

Ever growing volume and velocity of data coupled with decreasing attention span of end users underscore the critical need for real-time analytics. In this regard, anomaly detection plays a key role as an application as well as a means to…

Machine Learning · Statistics 2017-10-16 Dhruv Choudhary , Arun Kejariwal , Francois Orsini

Labeled data sets are necessary to train and evaluate anomaly-based network intrusion detection systems. This work provides a focused literature survey of data sets for network-based intrusion detection and describes the underlying packet-…

Cryptography and Security · Computer Science 2019-07-09 Markus Ring , Sarah Wunderlich , Deniz Scheuring , Dieter Landes , Andreas Hotho

Sophisticated malware authors can sneak hidden malicious code into portable executable files, and this code can be hard to detect, especially if encrypted or compressed. However, when an executable file switches between code regimes (e.g.…

Cryptography and Security · Computer Science 2018-02-05 Michael Wojnowicz , Glenn Chisholm , Matt Wolff , Xuan Zhao

Detecting the anomaly behaviors such as network failure or Internet intentional attack in the large-scale Internet is a vital but challenging task. While numerous techniques have been developed based on Internet traffic in past years,…

Networking and Internet Architecture · Computer Science 2017-10-18 Jinfa Wang , Siyuan Jia , Hai Zhao , Jiuqiang Xu , Chuan Lin

Information flow analysis is a powerful technique for reasoning about the sensitive information exposed by a program during its execution. While past work has proposed information theoretic metrics (e.g., Shannon entropy, min-entropy,…

Cryptography and Security · Computer Science 2010-09-22 Ji Zhu , Mudhakar Srivatsa