Related Experiment Video
Updated: Oct 17, 2025

Applications of EEG Neuroimaging Data: Event-related Potentials, Spectral Power, and Multiscale Entropy
Published on: June 27, 2013
Identification of Distributed Denial of Services Anomalies by Using Combination of Entropy and Sequential
Basheer Husham Ali1,2, Nasri Sulaiman1, Syed Abdul Rahman Al-Haddad3
1Department of Electrical and Electronic Engineering, Faculty of Engineering, Universiti Putra Malaysia, Serdang 43400, Malaysia.
A new method combining entropy and sequential probabilities ratio test (ESPRT) effectively detects distributed denial of services (DDoS) attacks. This approach reduces uncertainty and false positives, enhancing network security against malicious traffic.
Area of Science:
- Computer Science
- Cybersecurity
- Network Security
Background:
- Distributed Denial of Services (DDoS) attacks pose significant threats to computer systems by overwhelming them with traffic.
- Existing entropy-based detection methods can suffer from threshold-dependent accuracy and higher false positive rates.
Purpose of the Study:
- To implement and evaluate a novel method for identifying malicious traffic and network interfaces involved in DDoS attacks.
- To improve the accuracy and reduce false positives in DDoS detection compared to traditional methods.
Main Methods:
- Developed a Java-based method integrating entropy (E) and sequential probabilities ratio test (SPRT).
- Utilized traffic grouping based on window size for entropy calculation.
- Evaluated the method using DARPA 1998, DARPA2000, and CIC-DDoS2019 datasets.
Main Results:
- The combined entropy and SPRT (ESPRT) method eliminated uncertainty associated with entropy thresholds.
- ESPRT demonstrated reduced false positive rates.
- Achieved high accuracy (e.g., 0.995) and F-scores (e.g., 0.997) on the DARPA 1998 dataset with specific window sizes.
- Showcased scalability for multi-domain topology applications.
Conclusions:
- The ESPRT method offers a robust and more reliable solution for detecting DDoS attacks.
- Combining entropy with SPRT significantly enhances detection performance and reduces false alarms.
- The method is effective across different datasets and adaptable to complex network environments.
Related Concept Videos
Wald-Wolfowitz Runs Test II
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
Distribution Reliability and Automation
The Anderson-Darling Test
Wald-Wolfowitz Runs Test I
The test works...
Probability Distributions
A discrete probability distribution is a probability distribution of discrete random variables. It can be categorized into binomial probability distribution and Poisson...
Unusual Results
According to the range rule of thumb, any value above or below two standard deviations, 2σ from the mean, μ is considered unusual.
Maximum unusual value =...

