Intrusion detection using variable-length audit trail patterns

被引:0
|
作者
Wespi, A [1 ]
Dacier, M [1 ]
Debar, H [1 ]
机构
[1] IBM Res, Zurich Res Lab, CH-8803 Ruschlikon, Switzerland
关键词
intrusion detection; Teiresias; pattern discovery; pattern matching; variable-length patterns; C2 audit trail; functionality verification tests;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Audit trail patterns generated on behalf of a Unix process can be used to model the process behavior. Most of the approaches proposed so far use a table of fixed-length patterns to represent the process model. However, variable-length patterns seem to be more naturally suited to model the process behavior, but they are also more difficult to construct. In this paper, we present a novel technique to build a table of variable-length patterns. This technique is based on Teiresias, an algorithm initially developed for discovering rigid patterns in unaligned biological sequences. We evaluate the quality of our technique in a testbed environment, and compare it with the intrusion-detection system proposed by Forrest et al. [8], which is based on fixed-length patterns. The results achieved with our novel method are significantly better than those obtained with the original method based on fixed-length patterns.
引用
收藏
页码:110 / 129
页数:20
相关论文
共 50 条
  • [21] VARIABLE-LENGTH GUNN OSCILLATOR
    MYERS, FA
    MCSTAY, J
    TAYLOR, BC
    ELECTRONICS LETTERS, 1968, 4 (18) : 386 - &
  • [22] REVERSIBLE VARIABLE-LENGTH CODES
    TAKISHIMA, Y
    WADA, M
    MURAKAMI, H
    IEEE TRANSACTIONS ON COMMUNICATIONS, 1995, 43 (2-4) : 158 - 162
  • [23] VARIABLE-LENGTH BINARY ENCODINGS
    GILBERT, EN
    MOORE, EF
    BELL SYSTEM TECHNICAL JOURNAL, 1959, 38 (04): : 933 - 967
  • [24] The synchronization of variable-length codes
    Titchener, MR
    IEEE TRANSACTIONS ON INFORMATION THEORY, 1997, 43 (02) : 683 - 691
  • [25] Dictionaries Using Variable-Length Keys and Data, with Applications
    Blandford, Daniel K.
    Blelloch, Guy E.
    PROCEEDINGS OF THE SIXTEENTH ANNUAL ACM-SIAM SYMPOSIUM ON DISCRETE ALGORITHMS, 2005, : 1 - 10
  • [26] A fast variable-length decoder using plane separation
    Jeon, JH
    Park, YS
    Park, HW
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2000, 10 (05) : 806 - 812
  • [27] VARIABLE-LENGTH STATIC SHIFT
    TAN, B
    ELECTRONIC ENGINEERING, 1987, 59 (726): : 26 - &
  • [28] Variable-length contexts for PPM
    Skibinski, P
    Grabowski, S
    DCC 2004: DATA COMPRESSION CONFERENCE, PROCEEDINGS, 2004, : 409 - 418
  • [29] On the motion of a variable-length pendulum
    1600, Alexandria University, Alexandria, Egypt (34):
  • [30] VARIABLE-LENGTH SHIFT REGISTER
    NAGARAJ, K
    SINGHAL, K
    ELECTRONICS LETTERS, 1985, 21 (10) : 452 - 453