This is a placeholder for some ideas I have had regarding entropy drift and data content. Thre has been no time for any real work to happen, but once the data setup for the LNKnet software is complete, am thinking that it would make for good raw data for this analysis.
Initial thoughts (yes it is late, yes I have had too much coffee)churn around the idea of measuring the change in "data content" of system data set rather than watching the direct (or statistical) relatonship of each of the data elements. This is a more generic metric to monitor and perhaps will be less problamatic to set up in the long term vs. pattern matching or statistical systems. Remember the coffee ...
A short internet search indicates that a pair or researchers at North Carolina State University have beaten me to the punch for this analysis. Good thing too. Wenke Lee and Dong Xiang have written a decisave paper on "Information-Theoretic Measures for Anomaly Detection". I plan to re-read and try my hand at this analysis.