Publication | Closed Access
A sense of self for Unix processes
838
Citations
9
References
2002
Year
Unknown Venue
Anomaly DetectionEngineeringInformation SecuritySystem ProgrammingAutonomyFormal VerificationSoftware AnalysisHardware SecuritySelf-managing SystemSystems EngineeringNormal BehaviourUnix ProcessesSelf-aware SystemIntrusion Detection SystemThreat DetectionIntrusion ToleranceComputer ScienceSoftware DesignData SecurityCryptographySoftware SecurityProgram AnalysisFormal MethodsIntrusion DetectionShort-range Correlations
A method for anomaly detection is introduced in which "normal" is defined by short-range correlations in a process' system calls. Initial experiments suggest that the definition is stable during normal behaviour for standard UNIX programs. Further; it is able to detect several common intrusions involving sendmail and 1pr. This work is part of a research program aimed at building computer security systems that incorporate the mechanisms and algorithms used by natural immune systems.
| Year | Citations | |
|---|---|---|
Page 1
Page 1