DocumentCode
1813954
Title
Fuzzy Intrusion Detection System via Data Mining Technique with Sequences of System Calls
Author
Sekeh, Mohammad Akbarpour ; Bin Maarof, M.A.
Author_Institution
Dept. of Comput. Syst. & Commun., UTM, Skudai, Malaysia
Volume
1
fYear
2009
fDate
18-20 Aug. 2009
Firstpage
154
Lastpage
157
Abstract
There are two main approaches for implementing IDS; host based and network based. While the former is implemented in the form of software deployed on a host, the latter, usually is built as a hardware product with its own hardware platform (IDS appliance). In this paper, a host based intrusion detection system, that uses the idea of tracing system calls, is introduced. As a program runs, it uses the services of the underlying operating system to do some system calls. This system does not exactly need to know the program codes of each process. Normal and intrusive behaviors are collected with gathering the sequences of system calls for each process. Analysis of data is done via data mining and fuzzy techniques. Data mining is used to extract the normal behavior. The proposed system is shown to improve the performance, and decrease size of database, time complexity, and the rate of false alarms.
Keywords
data analysis; data mining; security of data; data analysis; data mining technique; fuzzy intrusion detection system; host based intrusion detection system; system calls; time complexity; Computer science; Data mining; Data security; Databases; Detectors; Fuzzy systems; Hardware; Intrusion detection; Operating systems; Turing machines; Data mining; Fuzzy; Operating system; Process-based Intrusion Detection; kernel; system calls;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security, 2009. IAS '09. Fifth International Conference on
Conference_Location
Xi´an
Print_ISBN
978-0-7695-3744-3
Type
conf
DOI
10.1109/IAS.2009.32
Filename
5283792
Link To Document