Streaming Estimation of Information-Theoretic Metrics for Anomaly Detection (Extended Abstract)

  • Authors:
  • Sergey Bratus;Joshua Brody;David Kotz;Anna Shubina

  • Affiliations:
  • Institute for Security Technology Studies Department of Computer Science, Dartmouth College, USA;Institute for Security Technology Studies Department of Computer Science, Dartmouth College, USA;Institute for Security Technology Studies Department of Computer Science, Dartmouth College, USA;Institute for Security Technology Studies Department of Computer Science, Dartmouth College, USA

  • Venue:
  • RAID '08 Proceedings of the 11th international symposium on Recent Advances in Intrusion Detection
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information-theoretic metrics hold great promise for modeling traffic and detecting anomalies if only they could be computed in an efficient, scalable way. Recent advances in streaming estimation algorithms give hope that such computations can be made practical. We describe our work in progress that aims to use streaming algorithms on 802.11a/b/g link layer (and above) features and feature pairs to detect anomalies.