@inproceedings{11666ed4c7f24b388f880fef72bb892e,
title = "Identifying network traffic features suitable for honeynet data analysis",
abstract = "A honeynet is a solution designed by the Honeynet Project organization to gather information on security threats and it can be used to proactively improve network security. A honeynet captures a substantial amount of data and logs for analysis in order to identify malicious activities and this is a challenging task. The main aim of this work is to identify the best traffic features or parameters that can be used in an anomaly detection technique to identify anomalies in honeynet traffic. In this work, a detailed analysis of feature-based and volume-based parameters is carried out and the most appropriate features for honeynet traffic are selected. Unlike other techniques proposed in the literature, our work combines entropy distributions for feature-based parameters and volume distributions for volume-based parameters to evaluate the different features. The features were evaluated using real honeynet traces released by the Honeynet project organization and other sources.",
keywords = "entropy, feature evaluation, Honeynet Traffic, network forensics, network security",
author = "Sqalli, {Mohammed H.} and Firdous, {Syed Naeem} and Khaled Salah and Marwan Abu-Amara",
year = "2011",
doi = "10.1109/CCECE.2011.6030620",
language = "British English",
isbn = "9781424497898",
series = "Canadian Conference on Electrical and Computer Engineering",
pages = "1044--1048",
booktitle = "2011 Canadian Conference on Electrical and Computer Engineering, CCECE 2011",
note = "2011 Canadian Conference on Electrical and Computer Engineering, CCECE 2011 ; Conference date: 08-05-2011 Through 11-05-2011",
}