Intrusion detection using variable-length audit trail patterns

被引:0
|
作者
Wespi, A [1 ]
Dacier, M [1 ]
Debar, H [1 ]
机构
[1] IBM Res, Zurich Res Lab, CH-8803 Ruschlikon, Switzerland
关键词
intrusion detection; Teiresias; pattern discovery; pattern matching; variable-length patterns; C2 audit trail; functionality verification tests;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Audit trail patterns generated on behalf of a Unix process can be used to model the process behavior. Most of the approaches proposed so far use a table of fixed-length patterns to represent the process model. However, variable-length patterns seem to be more naturally suited to model the process behavior, but they are also more difficult to construct. In this paper, we present a novel technique to build a table of variable-length patterns. This technique is based on Teiresias, an algorithm initially developed for discovering rigid patterns in unaligned biological sequences. We evaluate the quality of our technique in a testbed environment, and compare it with the intrusion-detection system proposed by Forrest et al. [8], which is based on fixed-length patterns. The results achieved with our novel method are significantly better than those obtained with the original method based on fixed-length patterns.
引用
收藏
页码:110 / 129
页数:20
相关论文
共 50 条
  • [31] PROCESSING VARIABLE-LENGTH ABBREVIATIONS
    MINCY, JW
    THARP, AL
    SOFTWARE-PRACTICE & EXPERIENCE, 1984, 14 (04): : 397 - 398
  • [32] VARIABLE-LENGTH SHIFT REGISTER
    JEFFERY, J
    ELECTRONICS & WIRELESS WORLD, 1986, 92 (1607): : 42 - 42
  • [33] A SPHINCTEROTOME WITH VARIABLE-LENGTH WIRE
    COTTON, PB
    CUNNINGHAM, J
    GASTROINTESTINAL ENDOSCOPY, 1995, 42 (05) : 494 - 494
  • [34] GrammarViz 3.0: Interactive Discovery of Variable-Length Time Series Patterns
    Senin, Pavel
    Lin, Jessica
    Wang, Xing
    Oates, Tim
    Gandhi, Sunil
    Boedihardjo, Arnold P.
    Chen, Crystal
    Frankenstein, Susan
    ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2018, 12 (01)
  • [35] Iterative construction of reversible variable-length codes and variable-length error-correcting codes
    Wang, J
    Yang, LL
    Hanzo, L
    IEEE COMMUNICATIONS LETTERS, 2004, 8 (11) : 671 - 673
  • [36] Variable-Length Multivariate Time Series Classification Using ROCKET: A Case Study of Incident Detection
    Bier, Agnieszka
    Jastrzebska, Agnieszka
    Olszewski, Pawel
    IEEE ACCESS, 2022, 10 : 95701 - 95715
  • [37] NEXT cancellation in xDSL systems using variable-length cancellers
    Nongpiur, RC
    Shpak, DJ
    Antoniou, A
    PROCEEDINGS OF THE 2003 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOL IV: DIGITAL SIGNAL PROCESSING-COMPUTER AIDED NETWORK DESIGN-ADVANCED TECHNOLOGY, 2003, : 345 - 348
  • [38] Cooperative Multi-Sensor Detection under Variable-Length Coding
    Hamad, Mustapha
    Wigger, Michele
    Sarkiss, Mireille
    2020 IEEE INFORMATION THEORY WORKSHOP (ITW), 2021,
  • [39] Variable-length sequential dynamic features-based malware detection
    Du D.
    Li G.
    Ma Y.
    Du, Donggao (dudonggao@126.com), 1600, Inst. of Scientific and Technical Information of China (22): : 362 - 367
  • [40] Multilocus association mapping using variable-length Markov chains
    Browning, Sharon R.
    AMERICAN JOURNAL OF HUMAN GENETICS, 2006, 78 (06) : 903 - 913