首页> 美国政府科技报告 >High Order Non-Stationary Markov Models and Anomaly Propagation Analysis in Intrusion Detection System (IDS)
【24h】

High Order Non-Stationary Markov Models and Anomaly Propagation Analysis in Intrusion Detection System (IDS)

机译:入侵检测系统(IDs)中的高阶非平稳马尔可夫模型和异常传播分析

获取原文

摘要

A new concept targeted to decrease false positive rates of anomaly based intrusion detection operating in the system call domain is proposed. To mitigate false positives, network based correlation of collected anomalies from different hosts is suggested, as well as a new means of host-based anomaly detection. The concept of anomaly propagation is based on the premise that false alarms do not propagate within the network. Unless anomaly propagation is observed, alarms are to be treated as false positives. The rationale behind the concept lies in the fact that the most common feature of worms and viruses is self-replication. As replication takes place, a malicious code propagating through the network would carry out the same activity resulting in almost identical system call sequences and triggering the same alarm at different hosts. The alarm propagation effect can be used to distinguish true alarms from false positives . At the host-level, a new anomaly detection mechanism operating that employs non-stationary Markov models is proposed.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号