arrow
Return

Detecting Intrusions through System Call Sequence and Argument Analysis

delete2010-10-01
delete77
delete
OA
AI
F
Federico Maggi *
M
Matteo Matteucci
S
Stefano Zanero
DOI:10.1109/TDSC.2008.69delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
We describe an unsupervised host-based intrusion detection system based on system call arguments and sequences. We define a set of anomaly detection models for the individual parameters of the call. We then describe a clustering process that helps to better fit models to system call arguments and creates interrelations among different arguments of a system call. Finally, we add a behavioral Markov model in order to capture time correlations and abnormal behaviors. The whole system needs no prior knowledge input; it has a good signal-to-noise ratio, and it is also able to correctly contextualize alarms, giving the user more information to understand whether a true or false positive happened, and to detect global variations over the entire execution flow, as opposed to punctual ones over individual instances.
Keywords:
Intrusion detection
anomaly detection
behavior detection
Markov models
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

P
Polytechnic University of Milan
Scholars:
2.0W
Papers: 1.8W
Citations: 24