Towards Building a Masquerade Detection Method Based on User File System Navigation

被引:0
|
作者
Camina, Benito [1 ]
Monroy, Raul [1 ]
Trejo, Luis A. [1 ]
Sanchez, Erika [1 ]
机构
[1] Tecnol Monterrey, Dept Comp Sci, Atizapan 52926, Estado De Mexic, Mexico
来源
关键词
INTRUSION;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Given that information is an extremely valuable asset, it is vital to timely detect whether one's computer (session) is being illegally seized by a masquerader. Masquerade detection has been actively studied for more than a decade, especially after the seminal work of Schonlau's group, who suggested that, to profile a user, one should model the history of the commands she would enter into a UNIX session. Schonlau's group have yielded a masquerade dataset, which has been the standard for comparing masquerade detection methods. However, the performance of these methods is not conclusive, and, as a result, research on masquerade detection has resorted to other sources of information for profiling user behaviour. In this paper, we show how to build an accurate user profile by looking into how the user structures her own file system and how she navigates such structure. While preliminary, our results are encouraging and suggest a number of ways in which new methods can be constructed.
引用
收藏
页码:174 / 186
页数:13
相关论文
共 50 条
  • [41] New fault detection method for the integrated navigation system
    Tao, J.Y.
    Tao, L.M.
    Yang, D.X.
    2001, National University of Defense Technology (23):
  • [42] A CDP method in Object-based file system
    Yao, Jie
    Cao, Qiang
    Li, Huaiyang
    EIGHTH INTERNATIONAL SYMPOSIUM ON OPTICAL STORAGE AND 2008 INTERNATIONAL WORKSHOP ON INFORMATION DATA STORAGE, 2009, 7125
  • [43] Masquerade detection system based on principal component analysis and radial basics function
    Li, ZC
    Li, ZT
    Li, Y
    Liu, B
    COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 309 - 314
  • [44] Masquerade detection system based on Correlation Eigen Matrix and support vector machine
    Li, Zhanchun
    Li, Zhitang
    Liu, Bin
    2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 625 - 628
  • [45] Towards building a learning based knowledge system
    Kumar, V.R.
    Mani, N.
    Advances in Modelling and Analysis B: Signals, Information, Data, Patterns, 1994, 30 (3-4): : 1 - 6
  • [46] A hierarchical fault detection method based on LS-SVM in integrated navigation system
    Chen, Chang-Xing
    Wang, Xu-Jing
    Niu, Dezhi
    Ren, Xiao-Yue
    Qu, Kun
    Sensors and Transducers, 2014, 175 (07): : 111 - 116
  • [47] A Fault Detection Method for GNSS/INS Integrated Navigation System Based on GARCH Model
    Cong, Li
    Li, Xin
    Yang, Xingguang
    Huang, Xiaoyang
    Xue, Rui
    Tsai, Yung-Fu
    PROCEEDINGS OF THE ION 2015 PACIFIC PNT MEETING, 2015, : 713 - 718
  • [48] Update of file-system-based navigation databases -: A generic framework for the processing of update data for navigation systems
    Luedtke, Dirk
    Starke, Alexander
    2008 IEEE 67TH VEHICULAR TECHNOLOGY CONFERENCE-SPRING, VOLS 1-7, 2008, : 3006 - +
  • [49] Towards building a fault tolerant and conflict-free distributed file system for mobile clients
    Boukerche, Azzedine
    Al-Shaikh, Raed
    20TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 2, PROCEEDINGS, 2006, : 405 - +
  • [50] URFS: A User-space Raw File System based on NVMe SSD
    Tu, Yaofeng
    Han, Yinjun
    Chen, Zhenghua
    Chen, Zhengguang
    Chen, Bing
    2020 IEEE 26TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2020, : 494 - 501