On-line Intrusion Detection Using Sequences of System Calls

نویسندگان

  • Damon Snyder
  • Robert van Engelen
  • Kyle Gallivan
  • DAMON SNYDER
  • Theodore P. Baker
چکیده

This thesis investigates the use of anomaly dete tion te hniques for on-line intrusion dete tion. A detailed analysis of methods introdu ed by Forrest et al. is presented and an improved hara terization of intrusions is derived. A novel approa h to integrating this hara terization into an on-line intrusion dete tion system is developed and implemented. Finally, experiments examining the eÆ ien y, exibility and eÆ a y of the system are presented. viii CHAPTER

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Hybrid Framework for Building an Efficient Incremental Intrusion Detection System

In this paper, a boosting-based incremental hybrid intrusion detection system is introduced. This system combines incremental misuse detection and incremental anomaly detection. We use boosting ensemble of weak classifiers to implement misuse intrusion detection system. It can identify new classes types of intrusions that do not exist in the training dataset for incremental misuse detection. As...

متن کامل

Incremental Bayesian Segmentation for Intrusion Detection

This thesis describes an attempt to monitor patterns of system calls generated by a Unix host in order to detect potential intrusion attacks. Sequences of system calls generated by privileged processes are analyzed using incremental Bayesian segmentation in order to detect anomalous activity. Theoretical analysis of various aspects of the algorithm and empirical analysis of performance on synth...

متن کامل

Intrusion Detection using Text Processing Techniques with a Binary-Weighted Cosine Metric

This paper introduces a new similarity measure, termed Binary Weighted Cosine (BWC) metric, for anomaly-based intrusion detection schemes that rely on using sequences of system calls. The new similarity measure considers both the number of shared system calls between two processes as well as frequencies of those calls. The k nearest neighbor (kNN) classifier is used to categorize a process as e...

متن کامل

Learning Classifiers for Misuse Detection Using a Bag of System Calls Representation

In this paper, we propose a “bag of system calls” representation for intrusion detection of system call sequences and describe misuse detection results with widely used machine learning techniques on University of New Mexico (UNM) and MIT Lincoln Lab (MIT LL) system call sequences with the proposed representation. With the feature representation as input, we compare the performance of several m...

متن کامل

Detecting Intrusions Using System Calls: Alternative Data Modelsy

Intrusion detection systems rely on a wide variety of observable data to distinguish between legitimate and illegitimate activities. In this paper we study one such observable— sequences of system calls into the kernel of an operating system. Using system-call data sets generated by several different programs, we compare the ability of different data modeling methods to represent normal behavio...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2001