A tfidfvectorizer and singular value decomposition based host intrusion detection system framework for detecting anomalous system processes

A tfidfvectorizer and singular value decomposition based host intrusion detection system framework for detecting anomalous system processes
复制标题

DOI:
10.1016/j.cose.2020.102084
复制
发表时间:
2021
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Basant Subba;Prakriti Gupta
Basant Subba;Prakriti Gupta
中科院分区:
其他
文献类型:
--
作者:
Basant Subba;Prakriti Gupta

文献摘要

被引文献

相似文献

基于主机的入侵检测系统(HIDS)是提供全面安全解决方案的不可或缺的工具。它们能够检测到主机特定的攻击,而这些攻击无法使用基于网络的入侵检测系统(NIDS)检测到。提出了一种新的基于向量化和截断奇异值分解的主机入侵检测系统(HIDS)框架,用于真实的实时识别异常系统进程。该框架以系统调用跟踪文件为输入,将其转换为语法特征向量表示模型。然后,该框架使用一种称为thefidfvectorizer的矢量化技术来计算变换后的特征向量的thefidf值。然后,使用基于它们的fidf值的截断SVD对变换后的gram特征向量进行简化。最后将降维的向量化的n-gram特征向量作为输入提供给各种基于机器学习的分类器模型,以确定相应的系统调用跟踪文件是正常的还是异常的。在基准数据集ADFA-LD和ADFA-WD上的实验结果表明,该HIDS框架能够有效地检测异常系统进程,具有较高的准确率和较低的处理开销。它也被证明优于其他HIDS框架中提出的文献。
Host based intrusion detection systems (HIDSs) are indispensable tools for providing a comprehensive security solution. They are capable of detecting host specific attacks, which cannot be detected using network based intrusion detection systems (NIDSs). This paper proposes a noveltfidfvectorizerand truncatedsingular valuedecomposition(SVD) based host intrusion detection system (HIDS) framework for identification of anomalous system processes in real time. The proposed HIDS framework takes the system call trace files as its input and transforms them inton-gramfeature vector representational models. The framework then uses a vectorization technique called thetfidfvectorizerto compute thetfidfvalues of then-gramterms of the transformed feature vectors. Dimensionality reduction of the transformedn-gramfeature vectors are then carried out using truncated SVD based on theirtfidfvalues. The dimensionality reducedtfidfvectorized n-gramfeature vectors are finally provided as inputs to various machine learning based classifier models to determine whether the corresponding system call trace files are normal or anomalous. Experimental results on the benchmark ADFA-LD and ADFA-WD datasets show that the proposed HIDS framework effectively detects anomalous system processes with high accuracy and low processing overhead. It is also shown to outperform other HIDS frameworks proposed in the literature.