Academic Journal
A Semantic Approach to Host-Based Intrusion Detection Systems Using Contiguousand Discontiguous System Call Patterns.
| Τίτλος: | A Semantic Approach to Host-Based Intrusion Detection Systems Using Contiguousand Discontiguous System Call Patterns. |
|---|---|
| Συγγραφείς: | Creech, Gideon, Hu, Jiankun |
| Πηγή: | IEEE Transactions on Computers; Apr2014, Vol. 63 Issue 4, p807-819, 13p |
| Θεματικοί όροι: | Semantic Web, Intrusion detection systems (Computer security), Pattern recognition systems, Constant false alarm rate (Data processing), Programming languages, Computer architecture |
| Περίληψη: | Host-based anomaly intrusion detection system design is very challenging due to the notoriously high false alarm rate. This paper introduces a new host-based anomaly intrusion detection methodology using discontiguous system call patterns, in an attempt to increase detection rates whilst reducing false alarm rates. The key concept is to apply a semantic structure to kernel level system calls in order to reflect intrinsic activities hidden in high-level programming languages, which can help understand program anomaly behaviour. Excellent results were demonstrated using a variety of decision engines, evaluating the KDD98 and UNM data sets, and a new, modern data set. The ADFA Linux data set was created as part of this research using a modern operating system and contemporary hacking methods, and is now publicly available. Furthermore, the new semantic method possesses an inherent resilience to mimicry attacks, and demonstrated a high level of portability between different operating system versions. [ABSTRACT FROM PUBLISHER] |
| Copyright of IEEE Transactions on Computers is the property of IEEE and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Βάση Δεδομένων: | Complementary Index |
| FullText | Links: – Type: other Text: Availability: 0 |
|---|---|
| Header | DbId: edb DbLabel: Complementary Index An: 95054880 RelevancyScore: 835 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 834.901184082031 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: A Semantic Approach to Host-Based Intrusion Detection Systems Using Contiguousand Discontiguous System Call Patterns. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Creech%2C+Gideon%22">Creech, Gideon</searchLink><br /><searchLink fieldCode="AR" term="%22Hu%2C+Jiankun%22">Hu, Jiankun</searchLink> – Name: TitleSource Label: Source Group: Src Data: IEEE Transactions on Computers; Apr2014, Vol. 63 Issue 4, p807-819, 13p – Name: Subject Label: Subject Terms Group: Su Data: <searchLink fieldCode="DE" term="%22Semantic+Web%22">Semantic Web</searchLink><br /><searchLink fieldCode="DE" term="%22Intrusion+detection+systems+%28Computer+security%29%22">Intrusion detection systems (Computer security)</searchLink><br /><searchLink fieldCode="DE" term="%22Pattern+recognition+systems%22">Pattern recognition systems</searchLink><br /><searchLink fieldCode="DE" term="%22Constant+false+alarm+rate+%28Data+processing%29%22">Constant false alarm rate (Data processing)</searchLink><br /><searchLink fieldCode="DE" term="%22Programming+languages%22">Programming languages</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+architecture%22">Computer architecture</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Host-based anomaly intrusion detection system design is very challenging due to the notoriously high false alarm rate. This paper introduces a new host-based anomaly intrusion detection methodology using discontiguous system call patterns, in an attempt to increase detection rates whilst reducing false alarm rates. The key concept is to apply a semantic structure to kernel level system calls in order to reflect intrinsic activities hidden in high-level programming languages, which can help understand program anomaly behaviour. Excellent results were demonstrated using a variety of decision engines, evaluating the KDD98 and UNM data sets, and a new, modern data set. The ADFA Linux data set was created as part of this research using a modern operating system and contemporary hacking methods, and is now publicly available. Furthermore, the new semantic method possesses an inherent resilience to mimicry attacks, and demonstrated a high level of portability between different operating system versions. [ABSTRACT FROM PUBLISHER] – Name: Abstract Label: Group: Ab Data: <i>Copyright of IEEE Transactions on Computers is the property of IEEE and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=95054880 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1109/TC.2013.13 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 13 StartPage: 807 Subjects: – SubjectFull: Semantic Web Type: general – SubjectFull: Intrusion detection systems (Computer security) Type: general – SubjectFull: Pattern recognition systems Type: general – SubjectFull: Constant false alarm rate (Data processing) Type: general – SubjectFull: Programming languages Type: general – SubjectFull: Computer architecture Type: general Titles: – TitleFull: A Semantic Approach to Host-Based Intrusion Detection Systems Using Contiguousand Discontiguous System Call Patterns. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Creech, Gideon – PersonEntity: Name: NameFull: Hu, Jiankun IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 04 Text: Apr2014 Type: published Y: 2014 Identifiers: – Type: issn-print Value: 00189340 Numbering: – Type: volume Value: 63 – Type: issue Value: 4 Titles: – TitleFull: IEEE Transactions on Computers Type: main |
| ResultId | 1 |