A Novel Similar Temporal System Call Pattern Mining for Efficient Intrusion Detection

被引:0
|
作者
Radhakrishna, Vangipuram [1 ]
Kumar, Puligadda Veereswara [2 ]
Janaki, Vinjamuri [3 ]
机构
[1] VNR Vignana Jyothi Inst Engn & Technol, Hyderabad, Andhra Pradesh, India
[2] Osmania Univ, Univ Coll Engn, Hyderabad, Andhra Pradesh, India
[3] Vaagdevi Engn Coll, Warangal, Andhra Pradesh, India
关键词
Intrusion; Malicious; System Call Pattern; Temporal; Similarity; Vulnerability;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software security pattern mining is the recent research interest among researchers working in the areas of security and data mining. When an application runs, several process and system calls associated are invoked in background. In this paper, the major objective is to identify the intrusion using temporal pattern mining. The idea is to find normal temporal system call patterns and use these patterns to identify abnormal temporal system call patterns. For finding normal system call patterns, we use the concept of temporal association patterns. The reference sequence is used to obtain temporal association system call patterns satisfying specified dissimilarity threshold. To find similar (normal) temporal system call patterns, we apply our novel method which performs only a single database scan, reducing unnecessary extra overhead incurred when multiple scans are performed thus achieving space and time efficiency. The importance of the approach coins from the fact that this is first single database scan approach in the literature. To find if a given process is normal or abnormal, it is just sufficient to verify if there exists a temporal system call pattern which is not similar to the reference system call support sequence for specified threshold. This eliminates the need for finding decision rules by constructing decision table. The approach is efficient as it eliminates the need for finding decision rules (2(n) is usually very large for even small value of n) and thus aims at efficient dimensionality reduction as we consider only similar temporal system call sequence for deciding on intrusion.
引用
收藏
页码:475 / 493
页数:19
相关论文
共 50 条
  • [1] An efficient mining algorithm for frequent pattern in intrusion detection
    Li, QH
    Xiong, JJ
    Yang, HB
    2003 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-5, PROCEEDINGS, 2003, : 138 - 142
  • [2] A Novel Intrusion Detection System Based on Data Mining
    Xu Tao
    Zhang Wei
    Li XuHong
    Wang Xia
    Pan Wenwen
    PROCEEDINGS OF THE 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER, MECHATRONICS, CONTROL AND ELECTRONIC ENGINEERING (ICCMCEE 2015), 2015, 37 : 1306 - 1309
  • [3] An intrusion detection method based on system call temporal serial analysis
    Pu, Shi
    Lang, Bo
    ADVANCED INTELLIGENT COMPUTING THEORIES AND APPLICATIONS: WITH ASPECTS OF THEORETICAL AND METHODOLOGICAL ISSUES, 2007, 4681 : 656 - +
  • [4] Efficient Mining of Temporal Safety Properties for Intrusion Detection in Industrial Control Systems
    Koucham, Oualid
    Mocanu, Stephane
    Hiet, Guillaume
    Thiriet, Jean-Marc
    Majorczyk, Frederic
    IFAC PAPERSONLINE, 2018, 51 (24): : 1043 - 1050
  • [5] Research on Efficient Pattern Matching Algorithms in Intrusion Detection System
    Liu-xiaoxing
    Yu-ning
    2014 7TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION (ICICTA), 2014, : 509 - 512
  • [6] A novel adaptive intrusion detection system based on data mining
    Yu, ZX
    Chen, JR
    Zhu, TQ
    PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 2390 - 2395
  • [7] An intrusion detection system based on system call
    Shen, Yue
    Yu, Fei
    Zhang, Ling-Fen
    An, Ji-Yao
    Zhu, Miao-Liang
    2005 1ST IEEE/IFIP INTERNATIONAL CONFERENCE IN CENTRAL ASIA ON INTERNET (ICI), 2005, : 150 - 153
  • [8] An efficient pattern mining approach for event detection in multivariate temporal data
    Batal, Iyad
    Cooper, Gregory F.
    Fradkin, Dmitriy
    Harrison, James, Jr.
    Moerchen, Fabian
    Hauskrecht, Milos
    KNOWLEDGE AND INFORMATION SYSTEMS, 2016, 46 (01) : 115 - 150
  • [9] An efficient pattern mining approach for event detection in multivariate temporal data
    Iyad Batal
    Gregory F. Cooper
    Dmitriy Fradkin
    James Harrison
    Fabian Moerchen
    Milos Hauskrecht
    Knowledge and Information Systems, 2016, 46 : 115 - 150
  • [10] Efficient and Distributed Temporal Pattern Mining
    Ho, Nguyen
    Van Long Ho
    Pedersen, Torben Bach
    Vu, Mai
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 335 - 343