首页> 外文会议>Exploiting the Knowledge Base: Applications of Rule Based Control >Considering both intra-pattern and inter-pattern anomalies for intrusion detection
【24h】

Considering both intra-pattern and inter-pattern anomalies for intrusion detection

机译:同时考虑模式内和模式间异常进行入侵检测

获取原文
获取原文并翻译 | 示例

摘要

Various approaches have been proposed to discover patterns from system call trails of UNIX processes to better model application behavior. However, these techniques only consider the relationship between system calls (or system audit events). We first refine the definition of maximal patterns given in (Wespi et al., 2000) and provide a pattern extraction algorithm to identify such maximal patterns. We then add one additional dimension to the problem domain by also taking into consideration the overlap relationship between patterns. We argue that an execution path of an application is usually not an arbitrary combination of various patterns; but rather, they overlap each other in some specific order. Such overlap relationship characterizes the normal behavior of the application. Finally, a novel pattern matching module is proposed to detect intrusions based on both intra-pattern and inter-pattern anomalies. We test this idea using the data sets obtained from the University of New Mexico. The experimental results indicate that our scheme detects significantly more anomalies than the scheme presented in (Wespi et al., 2000) while maintaining a very low false alarm rate.
机译:已经提出了各种方法来从UNIX进程的系统调用跟踪中发现模式,以更好地对应用程序行为进行建模。但是,这些技术仅考虑系统调用(或系统审核事件)之间的关系。我们首先完善(Wespi et al。,2000)中给出的最大模式的定义,并提供一种模式提取算法来识别这种最大模式。然后,我们还通过考虑模式之间的重叠关系,为问题域增加一个维度。我们认为,应用程序的执行路径通常不是各种模式的任意组合;但是,它们以某种特定顺序相互重叠。这种重叠关系表征了应用程序的正常行为。最后,提出了一种新型的模式匹配模块,用于基于模式内和模式间异常检测入侵。我们使用从新墨西哥大学获得的数据集来检验这种想法。实验结果表明,我们的方案比(Wespi et al。,2000)提出的方案检测到的异常明显多,同时保持了非常低的误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号