首页> 外文会议>International Congress on Image and Signal Processing >Evaluating host-based anomaly detection systems: A preliminary analysis of ADFA-LD
【24h】

Evaluating host-based anomaly detection systems: A preliminary analysis of ADFA-LD

机译:评估基于主机的异常检测系统:ADFA-LD的初步分析

获取原文

摘要

Host-based intrusion detection systems (HIDSs), especially anomaly-based, have received much attention over the past few decades. Over time, however, the existing data sets used for evaluation of a HIDS have lost most of their relevance due to the substantial development of computer systems. To fill this gap, ADFA Linux data set (ADFA-LD) is recently released, which is composed of thousands of system call traces collected from a contemporary Linux local server and expects to be a new benchmark for evaluating a HIDS. In this paper, we perform a preliminary analysis of ADFA-LD, in an attempt to extract useful information for developing new host-based anomaly detection systems (HADSs). In accordance with the general concerns arising from the community, some typical features are analysed particularly against ADFA-LD, such as length, common pattern and frequency. Furthermore, we implement a simple k nearest neighbour (kNN)-based HADS to be evaluated using ADFA-LD. The experimental results show that, although an acceptable performance can be acquired for a few types of attack, there is still a long way to fully understand the complex behaviour resulting from a modern computer system and, finally, realise more intelligent HADSs.
机译:在过去的几十年中,基于主机的入侵检测系统(HIDS),尤其是基于异常的入侵检测系统受到了广泛的关注。但是,随着时间的流逝,由于计算机系统的巨大发展,用于评估HIDS的现有数据集已经失去了大部分相关性。为了填补这一空白,最近发布了ADFA Linux数据集(ADFA-LD),该数据集由从现代Linux本地服务器收集的数千个系统调用跟踪组成,并有望成为评估HIDS的新基准。在本文中,我们对ADFA-LD进行了初步分析,以尝试提取有用的信息以开发新的基于主机的异常检测系统(HADS)。根据社区引起的普遍关注,分析了一些典型功能,尤其是针对ADFA-LD的功能,例如长度,通用模式和频率。此外,我们实现了一个简单的基于k最近邻(kNN)的HADS,可以使用ADFA-LD进行评估。实验结果表明,尽管对于几种类型的攻击都可以获得可接受的性能,但是要完全理解现代计算机系统所产生的复杂行为并最终实现更智能的HADS,还有很长的路要走。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号