Intrusion detection using variable-length audit trail patterns

被引:0
|
作者
Wespi, A [1 ]
Dacier, M [1 ]
Debar, H [1 ]
机构
[1] IBM Res, Zurich Res Lab, CH-8803 Ruschlikon, Switzerland
关键词
intrusion detection; Teiresias; pattern discovery; pattern matching; variable-length patterns; C2 audit trail; functionality verification tests;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Audit trail patterns generated on behalf of a Unix process can be used to model the process behavior. Most of the approaches proposed so far use a table of fixed-length patterns to represent the process model. However, variable-length patterns seem to be more naturally suited to model the process behavior, but they are also more difficult to construct. In this paper, we present a novel technique to build a table of variable-length patterns. This technique is based on Teiresias, an algorithm initially developed for discovering rigid patterns in unaligned biological sequences. We evaluate the quality of our technique in a testbed environment, and compare it with the intrusion-detection system proposed by Forrest et al. [8], which is based on fixed-length patterns. The results achieved with our novel method are significantly better than those obtained with the original method based on fixed-length patterns.
引用
收藏
页码:110 / 129
页数:20
相关论文
共 50 条
  • [41] Enhancement of the semisymbolic analysis precision using the variable-length arithmetic
    Dobes, J
    Míchal, J
    ICECS 2004: 11th IEEE International Conference on Electronics, Circuits and Systems, 2004, : 387 - 390
  • [42] Constellation Optimization Using an Evolutionary Algorithm with a Variable-length Chromosome
    Hitomi, Nozomi
    Selva, Daniel
    2018 IEEE AEROSPACE CONFERENCE, 2018,
  • [43] Variable-length sequential dynamic features-based malware detection
    杜冬高
    Li Gaochao
    Ma Yan
    HighTechnologyLetters, 2016, 22 (04) : 362 - 367
  • [44] Melody Composition Using Geometric Crossover for Variable-length Encoding
    Nam, Yong-Wook
    Kim, Yong-Hyuk
    PROCEEDINGS OF THE 2017 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE COMPANION (GECCO'17 COMPANION), 2017, : 37 - 38
  • [45] A VARIABLE-LENGTH RISC EMBEDDED ARCHITECTURE
    MCCARTNEY, D
    ELECTRONIC PRODUCT DESIGN, 1995, 16 (04): : 39 - &
  • [46] VARIABLE-LENGTH CODES AND FANO METRIC
    MASSEY, JL
    IEEE TRANSACTIONS ON INFORMATION THEORY, 1972, 18 (01) : 196 - +
  • [47] Learning variable-length representation of words
    Ganguly, Debasis
    PATTERN RECOGNITION, 2020, 103
  • [48] A VARIABLE-LENGTH SHIFT-REGISTER
    DANIELSSON, PE
    IEEE TRANSACTIONS ON COMPUTERS, 1983, 32 (11) : 1067 - 1069
  • [49] STATE SPLITTING FOR VARIABLE-LENGTH GRAPHS
    ADLER, R
    FRIEDMAN, J
    KITCHENS, B
    MARCUS, BH
    IEEE TRANSACTIONS ON INFORMATION THEORY, 1986, 32 (01) : 108 - 113
  • [50] Variable-length codes for error correction
    Jurgensen, H
    Konstantinidis, S
    AUTOMATA, LANGUAGES AND PROGRAMMING, 1995, 944 : 581 - 592