Entropy based intrusion detection which recognizes the network behavior only depends on the packets themselves and do not need any security background knowledge or user interventions, shows great appealing in network security areas. In this paper, we compare two entropy methods, network entropy and normalized relative network entropy (NRNE), to classify different network behaviors. The experimental results show although the two methods are efficient, the improved relative network entropy, NRNE is better which takes more attributes into consideration simultaneously and we can get an overall view of the abnormal network behavior.
Przemysław BerezińskiBartosz JasiulMarcin Szpyrka
Christian CallegariStefano GiordanoMichele Pagano
Yaling ZhangZhao-guo HanRen Jiao-xia