PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
November 13, 2002543 citations

Information-theoretic measures for anomaly detection

View Full Paper
WLWenke LeeDXDong Xiang

Key Points

Key points are not available for this paper at this time.

Abstract

Anomaly detection is an essential component of protection mechanisms against novel attacks. We propose to use several information-theoretic measures, namely, entropy, conditional entropy, relative conditional entropy, information gain, and information cost for anomaly detection. These measures can be used to describe the characteristics of an audit data set, suggest the appropriate anomaly detection model(s) to be built, and explain the performance of the model(s). We use case studies on Unix system call data, BSM data, and network tcpdump data to illustrate the utilities of these measures.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Lee et al. (2002) studied this question.

synapsesocial.com/papers/6a0f29435f469783126c9b15https://doi.org/10.1109/secpri.2001.924294
Ask AI
Helpful
Bookmark
Share
View Full Paper