首页> 外文会议>IEEE International Symposium on Software Reliability Engineering >A host-based anomaly detection approach by representing system calls as states of kernel modules
【24h】

A host-based anomaly detection approach by representing system calls as states of kernel modules

机译:通过将系统调用表示为内核模块状态的基于主机的异常检测方法

获取原文

摘要

Despite over two decades of research, high false alarm rates, large trace sizes and high processing times remain among the key issues in host-based anomaly intrusion detection systems. In an attempt to reduce the false alarm rate and processing time while increasing the detection rate, this paper presents a novel anomaly detection technique based on semantic interactions of system calls. The key concept is to represent system calls as states of kernel modules, analyze the state interactions, and identify anomalies by comparing the probabilities of occurrences of states in normal and anomalous traces. In addition, the proposed technique allows a visual understanding of system behaviour, and hence a more informed decision making. We evaluated this technique on Linux based programs of UNM datasets and a new modern Firefox dataset. We created the Firefox dataset on Linux using contemporary test suites and hacking techniques. The results show that our technique yields fewer false alarms and can handle large traces with smaller (or comparable) processing times compared against the existing techniques for the host based anomaly intrusion detection systems.
机译:尽管进行了超过二十年的研究,但基于主机的异常入侵检测系统的高误报率,较大的迹线大小和较高的处理时间仍然是关键问题。为了在提高检测率的同时减少误报率和处理时间,提出了一种基于系统调用语义交互的异常检测技术。关键概念是将系统调用表示为内核模块的状态,分析状态交互作用,并通过比较正常迹线和异常迹线中状态发生的概率来识别异常。此外,所提出的技术可以直观地了解系统的行为,从而可以更明智地进行决策。我们在基于Linux的UNM数据集程序和新的现代Firefox数据集上评估了该技术。我们使用现代测试套件和黑客技术在Linux上创建了Firefox数据集。结果表明,与基于主机的异常入侵检测系统的现有技术相比,我们的技术产生的虚假警报更少,并且能够以更短(或相当)的处理时间处理大量跟踪。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号