{"id":"https://openalex.org/W2168816538","doi":"https://doi.org/10.1109/ccece.2009.5090107","title":"Detection of anomalous packet traffic via entropy","display_name":"Detection of anomalous packet traffic via entropy","publication_year":2009,"publication_date":"2009-05-01","ids":{"openalex":"https://openalex.org/W2168816538","doi":"https://doi.org/10.1109/ccece.2009.5090107","mag":"2168816538"},"language":"en","primary_location":{"id":"doi:10.1109/ccece.2009.5090107","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ccece.2009.5090107","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2009 Canadian Conference on Electrical and Computer Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5019152518","display_name":"Anna T. \u0141awniczak","orcid":"https://orcid.org/0000-0002-2984-0877"},"institutions":[{"id":"https://openalex.org/I79817857","display_name":"University of Guelph","ror":"https://ror.org/01r7awg59","country_code":"CA","type":"education","lineage":["https://openalex.org/I79817857"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Anna T. Lawniczak","raw_affiliation_strings":["Department of Mathematics and Statistics, University of Guelph, Guelph, ONT, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Mathematics and Statistics, University of Guelph, Guelph, ONT, Canada","institution_ids":["https://openalex.org/I79817857"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101738348","display_name":"Hao Wu","orcid":"https://orcid.org/0009-0009-2999-417X"},"institutions":[{"id":"https://openalex.org/I79817857","display_name":"University of Guelph","ror":"https://ror.org/01r7awg59","country_code":"CA","type":"education","lineage":["https://openalex.org/I79817857"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Hao Wu","raw_affiliation_strings":["Department of Mathematics and Statistics, University of Guelph, Guelph, ONT, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Mathematics and Statistics, University of Guelph, Guelph, ONT, Canada","institution_ids":["https://openalex.org/I79817857"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5023406507","display_name":"Bruno N. Di Stefano","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bruno N. Di Stefano","raw_affiliation_strings":["Nuptek Systems Limited, Toronto, ONT, Canada"],"affiliations":[{"raw_affiliation_string":"Nuptek Systems Limited, Toronto, ONT, Canada","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5019152518"],"corresponding_institution_ids":["https://openalex.org/I79817857"],"apc_list":null,"apc_paid":null,"fwci":0.3428,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.66878006,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10138","display_name":"Network Traffic and Congestion Control","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/link-state-packet","display_name":"Link state packet","score":0.7604467272758484},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.7392884492874146},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7234653830528259},{"id":"https://openalex.org/keywords/denial-of-service-attack","display_name":"Denial-of-service attack","score":0.6457490921020508},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.6445358395576477},{"id":"https://openalex.org/keywords/packet-drop-attack","display_name":"Packet drop attack","score":0.549851655960083},{"id":"https://openalex.org/keywords/source-routing","display_name":"Source routing","score":0.5128824710845947},{"id":"https://openalex.org/keywords/processing-delay","display_name":"Processing delay","score":0.46651947498321533},{"id":"https://openalex.org/keywords/traffic-generation-model","display_name":"Traffic generation model","score":0.46328797936439514},{"id":"https://openalex.org/keywords/packet-analyzer","display_name":"Packet analyzer","score":0.43276044726371765},{"id":"https://openalex.org/keywords/routing-protocol","display_name":"Routing protocol","score":0.3816673457622528},{"id":"https://openalex.org/keywords/transmission-delay","display_name":"Transmission delay","score":0.3522217869758606},{"id":"https://openalex.org/keywords/routing-table","display_name":"Routing table","score":0.32986924052238464},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.3232824504375458},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.15460634231567383},{"id":"https://openalex.org/keywords/link-state-routing-protocol","display_name":"Link-state routing protocol","score":0.11400559544563293}],"concepts":[{"id":"https://openalex.org/C141947644","wikidata":"https://www.wikidata.org/wiki/Q3888408","display_name":"Link state packet","level":5,"score":0.7604467272758484},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.7392884492874146},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7234653830528259},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.6457490921020508},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.6445358395576477},{"id":"https://openalex.org/C35546906","wikidata":"https://www.wikidata.org/wiki/Q2900718","display_name":"Packet drop attack","level":5,"score":0.549851655960083},{"id":"https://openalex.org/C44010500","wikidata":"https://www.wikidata.org/wiki/Q1422567","display_name":"Source routing","level":5,"score":0.5128824710845947},{"id":"https://openalex.org/C21434264","wikidata":"https://www.wikidata.org/wiki/Q7247320","display_name":"Processing delay","level":4,"score":0.46651947498321533},{"id":"https://openalex.org/C176715033","wikidata":"https://www.wikidata.org/wiki/Q2080768","display_name":"Traffic generation model","level":2,"score":0.46328797936439514},{"id":"https://openalex.org/C95362637","wikidata":"https://www.wikidata.org/wiki/Q54366","display_name":"Packet analyzer","level":3,"score":0.43276044726371765},{"id":"https://openalex.org/C104954878","wikidata":"https://www.wikidata.org/wiki/Q1648707","display_name":"Routing protocol","level":3,"score":0.3816673457622528},{"id":"https://openalex.org/C108921912","wikidata":"https://www.wikidata.org/wiki/Q7834639","display_name":"Transmission delay","level":3,"score":0.3522217869758606},{"id":"https://openalex.org/C184896649","wikidata":"https://www.wikidata.org/wiki/Q290066","display_name":"Routing table","level":4,"score":0.32986924052238464},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3232824504375458},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.15460634231567383},{"id":"https://openalex.org/C89305328","wikidata":"https://www.wikidata.org/wiki/Q1755411","display_name":"Link-state routing protocol","level":4,"score":0.11400559544563293},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ccece.2009.5090107","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ccece.2009.5090107","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2009 Canadian Conference on Electrical and Computer Engineering","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":9,"referenced_works":["https://openalex.org/W1485063743","https://openalex.org/W1594317178","https://openalex.org/W2077678723","https://openalex.org/W2099048211","https://openalex.org/W2106796827","https://openalex.org/W2131693681","https://openalex.org/W2131956943","https://openalex.org/W2403171471","https://openalex.org/W6713222836"],"related_works":["https://openalex.org/W3011083237","https://openalex.org/W2183699885","https://openalex.org/W2202402999","https://openalex.org/W1765106989","https://openalex.org/W1996538372","https://openalex.org/W2075788514","https://openalex.org/W4384432930","https://openalex.org/W2617472281","https://openalex.org/W2220976990","https://openalex.org/W2991062139"],"abstract_inverted_index":{"We":[0],"study":[1],"if":[2,120],"information":[3,140],"entropy":[4,47,64,96,141],"of":[5,12,49,60,65,85,93,97,106,126,132,142],"packet":[6,17,26,51,66,80,98,138,143],"traffic":[7,18,52,67,81,139,144],"passing":[8],"through":[9],"selected":[10,55,149],"set":[11],"routers":[13,56,107,150],"may":[14,108],"detect":[15,117],"anomalous":[16,137],"(e.g.,":[19],"distributed":[20],"denial-of-service":[21],"(DDoS)":[22],"attacks)":[23],"in":[24,79],"a":[25,32,45,153],"switching":[27],"network":[28],"(PSN)":[29],"model.":[30,62],"Given":[31],"certain":[33],"PSN":[34,61],"model":[35],"setup":[36],"(i.e.,":[37],"topology,":[38],"routing":[39,122],"algorithm,":[40],"and":[41,111,135],"source":[42],"load":[43],"value)":[44],"ldquonaturalrdquo":[46,72],"profile":[48,73],"normal":[50,58],"monitored":[53,100,145],"at":[54,102,147],"characterizes":[57],"operation":[59],"When":[63],"deviates":[68],"significantly":[69,109],"from":[70],"this":[71],"it":[74,113],"means":[75],"that":[76,90,112],"some":[77],"anomaly":[78],"emerges.":[82],"Our":[83],"simulations":[84],"ping":[86],"DDoS":[87,133],"attacks":[88,94,134],"show":[89],"after":[91],"start":[92],"the":[95],"traffics":[99],"network-wide":[101,146],"relatively":[103],"small":[104],"sets":[105],"drop":[110],"is":[114,123],"easier":[115],"to":[116],"these":[118],"drops":[119],"static":[121],"used":[124],"instead":[125],"dynamic":[127],"routing.":[128],"Thus,":[129],"for":[130],"detection":[131],"other":[136],"properly":[148],"can":[151],"be":[152],"useful":[154],"tool.":[155]},"counts_by_year":[{"year":2015,"cited_by_count":1},{"year":2012,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
