A Hybrid Method to Intrusion Detection Systems Using HMM

A Hybrid Method to Intrusion Detection Systems Using HMM
复制标题

DOI:
10.1007/11604655_44
复制
发表时间:
2005-12
期刊:
--
影响因子:
--
通讯作者:
C. Raman;A. Negi
C. Raman;A. Negi
中科院分区:
其他
文献类型:
--
作者:
C. Raman;A. Negi

文献摘要

被引文献

相似文献

IDS使用不同的观察数据源和各种技术来区分良性和恶意行为。在当前的工作中,隐马尔可夫模型(HMM)的使用方式类似于它们在文本分类中的使用。该方法通过混合使用HMM和STIDE方法(子序列枚举)来执行基于主机的入侵检测。所建议的方法与STIDE的不同之处在于,使用由程序的正常运行发出的短序列系统调用,仅为所有应用程序的正常行为创建一个配置文件。在此之后,使用具有简单状态的HMM和STIDE将未知程序的系统调用序列分类为正常或入侵。对1998年DARPA数据的分析结果表明,该方法具有低假阳性率和高检出率的优点。
IDS use different sources of observation data and a variety of techniques to differentiate between benign and malicious behaviors. In the current work, Hidden Markov Models (HMM) are used in a manner analogous to their use in text categorization. The proposed approach performs host-based intrusion detection by using HMM along with STIDE methodology (enumeration of subsequences) in a hybrid fashion. The proposed method differs from STIDE in that only one profile is created for the normal behavior of all applications using short sequences of system calls issued by the normal runs of the programs. Subsequent to this, HMM with simple states along with STIDE is used to categorize an unknown program’s sequence of system calls to be either normal or an intrusion. The results on 1998 DARPA data show that the hybrid method results in low false positive rate with high detection rate.