DocumentCode :
2274003
Title :
Visualizing and identifying intrusion context from system calls trace
Author :
Li, Zhuowei ; Das, Amitabha
Author_Institution :
Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore
fYear :
2004
fDate :
6-10 Dec. 2004
Firstpage :
61
Lastpage :
70
Abstract :
Anomaly-based intrusion detection (AID) techniques are useful for detecting novel intrusions without known signatures. However, AID techniques suffer from higher false alarm rate compared to signature-based intrusion detection techniques. In this paper, the concept of intrusion context identification is introduced to address the problem. The identification of the intrusion context can help to significantly enhance the detection rate and lower the false alarm rate of AID techniques. To evaluate the effectiveness of the concept, a simple but representative scheme for intrusion context identification is proposed, in which the anomalies in the intrusive datasets are visualized first, and then the intrusion contexts are identified from the visualized anomalies. The experimental results show that using the scheme, the intrusion contexts can be visualized and extracted from the audit trails correctly. In addition, as an application of the visualized anomalies, an implicit design drawback in t-stide is found after careful analysis. Finally, based on the identified intrusion context and the efficiency comparison, several findings are made which can offer useful insights and benefit future research on AID techniques.
Keywords :
data visualisation; security of data; anomaly-based intrusion detection techniques; false alarm rate; intrusion context identification; intrusive datasets; system calls trace; visualized anomalies; Application software; Computer networks; Computer security; Filters; Intrusion detection; Protection; Sensor fusion; Visualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2004. 20th Annual
ISSN :
1063-9527
Print_ISBN :
0-7695-2252-1
Type :
conf
DOI :
10.1109/CSAC.2004.48
Filename :
1377216
Link To Document :
بازگشت