Title : 
The Evolution of System-Call Monitoring
         
        
            Author : 
Forrest, Stephanie ; Hofmeyr, Steven ; Somayaji, Anil
         
        
            Author_Institution : 
Dept. of Comput. Sci., Univ. of New Mexico, Albuquerque, NM
         
        
        
        
        
        
            Abstract : 
Computer security systems protect computers and networks from unauthorized use by external agents and insiders. The similarities between computer security and the problem of protecting a body against damage from externally and internally generated threats are compelling and were recognized as early as 1972 when the term computer virus was coined. The connection to immunology was made explicit in the mid 1990s, leading to a variety of prototypes, commercial products, attacks, and analyses. The paper reviews one thread of this active research area, focusing on system-call monitoring and its application to anomaly intrusion detection and response. The paper discusses the biological principles illustrated by the method, followed by a brief review of how system call monitoring was used in anomaly intrusion detection and the results that were obtained. Proposed attacks against the method are discussed, along with several important branches of research that have arisen since the original papers were published. These include other data modeling methods, extensions to the original system call method, and rate limiting responses. Finally, the significance of this body of work and areas of possible future investigation are outlined in the conclusion.
         
        
            Keywords : 
security of data; system monitoring; anomaly intrusion detection; computer security systems; system-call monitoring; Application software; Computer networks; Computer security; Computerized monitoring; Evolution (biology); Immune system; Intrusion detection; Protection; Prototypes; Yarn;
         
        
        
        
            Conference_Titel : 
Computer Security Applications Conference, 2008. ACSAC 2008. Annual
         
        
            Conference_Location : 
Anaheim, CA
         
        
        
            Print_ISBN : 
978-0-7695-3447-3
         
        
        
            DOI : 
10.1109/ACSAC.2008.54