...
首页> 外文期刊>The Journal of Systems and Software >Combining heterogeneous anomaly detectors for improved software security
【24h】

Combining heterogeneous anomaly detectors for improved software security

机译:结合异构检测器以提高软件安全性

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Host-based Anomaly Detection Systems (ADSs) monitor for significant deviations from normal software behavior. Several techniques have been investigated for detecting anomalies in system call sequences. Among these, Sequence Time-Delay Embedding (STIDE), Hidden Markov Model (HMM), and One-Class Support Vector Machine (OCSVM) have shown a high level of anomaly detection accuracy. Although ADSs can detect novel attacks, they generate a large number of false alarms due to the difficulty in obtaining complete descriptions of normal software behavior. This paper presents a multiple-detector ADS that efficiently combines the decisions from heterogeneous detectors (e.g., STIDE, HMM, and OCSVM), using Boolean combination in the Receiver Operating Characteristics (ROC) space, to reduce the false alarms. Results on two modern and large system call datasets generated from Linux and Windows operating systems show that the proposed ADS consistently outperforms an ADS based on a single best detector and on an ensemble of homogeneous detectors. At an operating point of zero percent alarm rate, the proposed multiple-detector ADS increased the true positive rate by 500% on the Linux dataset and by 25% on the Window dataset. Furthermore, the combinations of decisions from multiple heterogeneous detectors make the ADS more reliable and resilient against evasion and adversarial attacks.
机译:基于主机的异常检测系统(ADS)监视与正常软件行为的重大偏差。已经研究了几种检测系统调用序列中异常的技术。其中,序列时延嵌入(STIDE),隐马尔可夫模型(HMM)和一类支持向量机(OCSVM)已显示出高水平的异常检测精度。尽管ADS可以检测到新颖的攻击,但由于难以获得对正常软件行为的完整描述,因此它们会生成大量的错误警报。本文提出了一种多探测器ADS,它可以在接收器工作特性(ROC)空间中使用布尔组合,有效地组合来自异构探测器(例如STIDE,HMM和OCSVM)的决策,以减少错误警报。从Linux和Windows操作系统生成的两个现代大型系统调用数据集的结果表明,基于单个最佳检测器和同类检测器的集成,建议的ADS始终优于ADS。在零警报率的工作点上,建议的多探测器ADS在Linux数据集上将真实阳性率提高了500%,在Window数据集上提高了25%。此外,来自多个异构检测器的决策的组合使ADS更加可靠,更有弹性,可应对逃避和对抗性攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号