EconPapers    
Economics at your fingertips  
 

An unsupervised approach for traffic trace sanitization based on the entropy spaces

Pablo Velarde-Alvarado (), Cesar Vargas-Rosales (), Rafael Martinez-Pelaez (), Homero Toral-Cruz () and Alberto F. Martinez-Herrera ()
Additional contact information
Pablo Velarde-Alvarado: Autonomous University of Nayarit
Cesar Vargas-Rosales: Tecnológico de Monterrey
Rafael Martinez-Pelaez: Autonomous University of Ciudad Juarez
Homero Toral-Cruz: University of Quintana Roo
Alberto F. Martinez-Herrera: Tecnológico de Monterrey

Telecommunication Systems: Modelling, Analysis, Design and Management, 2016, vol. 61, issue 3, No 15, 609-626

Abstract: Abstract The accuracy and reliability of an anomaly-based network intrusion detection system are dependent on the quality of data used to build a normal behavior profile. However, obtaining these datasets is not trivial due to privacy, obsolescence, and suitability issues. This paper presents an approach to traffic trace sanitization based on the identification of anomalous patterns in a three-dimensional entropy space of the flow traffic data captured from a campus network. Anomaly-free datasets are generated by filtering out attacks and traffic pieces that modify the typical position of centroids in the entropy space. Our analyses were performed on real life traffic traces and show that the sanitized datasets have homogeneity and consistency in terms of cluster centroids and probability distributions of the PCA-transformed entropy space.

Keywords: Sanitizing traffic data; Entropy-based anomaly detection; Data mining; k-means clustering; Principal component analysis (search for similar items in EconPapers)
Date: 2016
References: View complete reference list from CitEc
Citations:

Downloads: (external link)
http://link.springer.com/10.1007/s11235-015-0017-6 Abstract (text/html)
Access to the full text of the articles in this series is restricted.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:spr:telsys:v:61:y:2016:i:3:d:10.1007_s11235-015-0017-6

Ordering information: This journal article can be ordered from
http://www.springer.com/journal/11235

DOI: 10.1007/s11235-015-0017-6

Access Statistics for this article

Telecommunication Systems: Modelling, Analysis, Design and Management is currently edited by Muhammad Khan

More articles in Telecommunication Systems: Modelling, Analysis, Design and Management from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().

 
Page updated 2025-03-20
Handle: RePEc:spr:telsys:v:61:y:2016:i:3:d:10.1007_s11235-015-0017-6