A Survey of Intrusion Detection Systems Leveraging Host Data

A Survey of Intrusion Detection Systems Leveraging Host Data
复制标题

DOI:
10.1145/3344382
复制
发表时间:
2020-01-01
影响因子:
16.6
通讯作者:
Chen, Qian (Guenevere)
Chen, Qian (Guenevere)
中科院分区:
计算机科学1区
文献类型:
--
作者:
Bridges, Robert A.;Glass-Vanderlan, Tarrah R.;Chen, Qian (Guenevere)

文献摘要

被引文献

相似文献

本调查的重点是入侵检测系统(IDS),利用基于主机的数据源来检测对企业网络的攻击。基于主机的入侵检测系统(HIDS)的文献是由输入数据源,提出有针对性的子调查的HIDS研究利用系统日志,审计数据,Windows注册表,文件系统和程序分析。虽然系统调用通常包含在审计数据中,但几个公开的系统调用数据集已经引发了一系列关于此主题的IDS研究,值得单独一节。为了适应当前的研究人员,一个部分给出了公开可用的数据集的描述,概述了它们的特点和缺点时,用于IDS评估。相关的调查进行了组织和说明。所有章节都附有表格,简要组织了所讨论的文献和数据集。最后,挑战、趋势和更广泛的观察贯穿于调查和结论中,沿着IDS研究的未来方向。总的来说,这项调查的目的是允许轻松访问主机上可用于感测入侵的各种类型的数据,使用每种数据的研究进展,以及该地区原型设计的可访问数据集。
This survey focuses on intrusion detection systems (IDS) that leverage host-based data sources for detecting attacks on enterprise network. The host-based IDS (HIDS) literature is organized by the input data source, presenting targeted sub-surveys of HIDS research leveraging system logs, audit data, Windows Registry, file systems, and program analysis. While system calls are generally included in audit data, several publicly available system call datasets have spawned a flurry of IDS research on this topic, which merits a separate section. To accommodate current researchers, a section giving descriptions of publicly available datasets is included, outlining their characteristics and shortcomings when used for IDS evaluation. Related surveys are organized and described. All sections are accompanied by tables concisely organizing the literature and datasets discussed. Finally, challenges, trends, and broader observations are throughout the survey and in the conclusion along with future directions of IDS research. Overall, this survey was designed to allow easy access to the diverse types of data available on a host for sensing intrusion, the progressions of research using each, and the accessible datasets for prototyping in the area.