Treffer: Entropy-based analyzing anomaly WEB traffic.

Title:
Entropy-based analyzing anomaly WEB traffic.
Authors:
Nasseralfoghara, Mehrdad1 (AUTHOR) mnaser1992@gmail.com, Hamidi, HamidReza1 (AUTHOR) hamidreza.hamidi@eng.ikiu.ac.ir
Source:
Journal of High Speed Networks. 2020, Vol. 26 Issue 4, p255-266. 12p.
Database:
Business Source Elite

Weitere Informationen

The application nature of HTTP protocol allows the creation of a covert timing channel based on different features of this protocol (or different levels) that has not been addressed in previous research. In this article, the entropy-based detection method was designed and implemented. The attacker can adjust the amount of channel entropy by controlling measures such as changing the channel's level or creating noise on the channel to protect from the analyzer's detection. As a result, the entropy threshold is not always constant for detection. By comparing the entropy from different levels of the channel and the analyzer, we concluded that the analyzer must investigate traffic at all possible levels. We also illustrated that by making noise on a covert channel, its capacity would decrease, but as entropy increases, it would be harder to detect it. [ABSTRACT FROM AUTHOR]

Copyright of Journal of High Speed Networks is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)

Volltext ist im Gastzugang nicht verfügbar.