跳到主要导航 跳到搜索 跳到主要内容

Profiling program behavior for anomaly intrusion detection based on the transition and frequency property of computer audit data

  • Xi'an Jiaotong University
  • Tsinghua University

科研成果: 期刊稿件文章同行评审

64 引用 (Scopus)

摘要

Intrusion detection is an important technique in the defense-in-depth network security framework. In recent years, it has been a widely studied topic in computer network security. In this paper, we present two methods, namely, the Hidden Markov Models (HMM) method and the Self Organizing Maps (SOM) method, to profile normal program behavior for anomaly intrusion detection based on computer audit data. The HMM method utilizes the transition property of events while SOM method relies on the frequency property of events. Two data sets, CERT synthetic Sendmail system call data collected in the University of New Mexico (UNM) and Live FTP system call data collected in the CNSIS lab of Xi'an Jiaotong University, were used to assess the two methods. Testing results show that the HMM method using the transition property of events produces good detection performance while high computational expense is required both for training and detection. The HMM method is better than other two methods reported previously in terms of detection accuracy for the same data set. The SOM method considering the frequency property of events, on the other hand, is suitable for real-time intrusion detection because of its capability of processing a large amount of data with low computational overhead.

源语言英语
页(从-至)539-550
页数12
期刊Computers and Security
25
7
DOI
出版状态已出版 - 10月 2006

学术指纹

探究 'Profiling program behavior for anomaly intrusion detection based on the transition and frequency property of computer audit data' 的科研主题。它们共同构成独一无二的学术指纹。

引用此