Detecting intrusions using system calls: alternative data models

Detecting intrusions using system calls: alternative data models
复制标题

DOI:
10.1109/secpri.1999.766910
复制
发表时间:
1999
期刊:
Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No.99CB36344)
影响因子:
--
通讯作者:
C. Warrender;S. Forrest;Barak A. Pearlmutter
C. Warrender;S. Forrest;Barak A. Pearlmutter
中科院分区:
其他
文献类型:
--
作者:
C. Warrender;S. Forrest;Barak A. Pearlmutter

文献摘要

被引文献

相似文献

入侵检测系统依赖于各种各样的可观察数据来区分合法和非法活动。我们研究这样一个可观察到的系统调用到操作系统的内核序列。使用几个不同的程序生成的系统调用数据集,我们比较了不同的数据建模方法的能力,以准确地表示正常的行为和识别入侵。我们比较了以下方法:观察到的序列的简单枚举;不同序列的相对频率的比较;规则归纳技术;和隐马尔可夫模型(HMM)。我们讨论了影响每种方法性能的因素,并得出结论,对于这个特定的问题,弱于障碍的方法可能是足够的。
Intrusion detection systems rely on a wide variety of observable data to distinguish between legitimate and illegitimate activities. We study one such observable-sequences of system calls into the kernel of an operating system. Using system-call data sets generated by several different programs, we compare the ability of different data modeling methods to represent normal behavior accurately and to recognize intrusions. We compare the following methods: simple enumeration of observed sequences; comparison of relative frequencies of different sequences; a rule induction technique; and hidden Markov models (HMMs). We discuss the factors affecting the performance of each method and conclude that for this particular problem, weaker methods than HMMs are likely sufficient.