Publication | Closed Access
Intrusion detection using sequences of system calls
1.3K
Citations
22
References
1998
Year
EngineeringInformation SecuritySoftware AnalysisFormal VerificationHardware SecuritySystem CallsTrusted Operating SystemNormal BehaviorPrivileged ProcessesThreat DetectionIntrusion Detection SystemIntrusion ToleranceOperating System SecurityComputer ScienceLanguage-based SecurityData SecuritySoftware SecurityProgram AnalysisSoftware TestingIntrusion DetectionSystem Software
A method is introduced for detecting intrusions at the level of privileged processes. Evidence is given that short sequences of system calls executed by running processes are a good discriminator between normal and abnormal operating characteristics of several common UNIX programs. Normal behavior is collected in two ways: Synthetically, by exercising as many normal modes of usage of a program as possible, and in a live user environment by tracing the actual execution of the program. In the former case several types of intrusive behavior were studied; in the latter case, results were analyzed for false positives.
| Year | Citations | |
|---|---|---|
Page 1
Page 1