IEEE Transactions on Dependable and Secure Computing · 2008 · 142 citations · 34 references
Anomaly DetectionEngineeringInformation SecuritySystem Call SequenceSoftware AnalysisFormal VerificationHardware SecurityData ScienceData MiningSystems EngineeringRuntime VerificationIntrusion Detection SystemThreat DetectionIntrusion ToleranceSystem Call ArgumentsAnomaly Detection ModelsComputer ScienceData SecurityProgram AnalysisIntrusion DetectionFormal MethodsSystem CallEvent-driven MonitoringSystem Software
We describe an unsupervised host-based intrusion detection system based on system call arguments and sequences. We define a set of anomaly detection models for the individual parameters of the call. We then describe a clustering process that helps to better fit models to system call arguments and creates interrelations among different arguments of a system call. Finally, we add a behavioral Markov model in order to capture time correlations and abnormal behaviors. The whole system needs no prior knowledge input; it has a good signal-to-noise ratio, and it is also able to correctly contextualize alarms, giving the user more information to understand whether a true or false positive happened, and to detect global variations over the entire execution flow, as opposed to punctual ones over individual instances.
34
Dorothy E. Denning · IEEE Transactions on Software Engineering · 1987 · 3.3K citations
Self-nonself discrimination in a computer
Stephanie Forrest, Alan S. Perelson, Luke R. Allen et al. · 2002 · 1.3K citations
Artificial Intelligence, Engineering, Information Security +19