• DocumentCode
    2399608
  • Title

    A new intrusion detection method based on process profiling

  • Author

    Okazaki, Yoshinori ; Sato, Izuru ; Goto, Shigeki

  • Author_Institution
    Matsushita Electr. Ind. Co. Ltd., Japan
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    82
  • Lastpage
    90
  • Abstract
    There are two well-known models for intrusion detection-anomaly intrusion detection (AID) model and misuse intrusion detection (MID) model. The former analyzes user behavior and the statistics of a process in a normal situation, and checks whether the system is being used in a different manner. The latter maintains a database of known intrusion techniques and detects intrusion by comparing behavior against the database. An intrusion detection method based on an AID model can detect a new intrusion method, but needs to update the data describing user behavior and statistics in normal usage. We call these information profiles. There are several problems in AID to be addressed. The profiles tend to be large. Detecting intrusion needs a large amount of system resources, like CPU time and memory and disk space. An MID model requires fewer system resources to detect intrusion. However, it cannot detect new, unknown intrusion methods. Our method solves these problems by recording system calls from daemon processes and setuid programs. We improved detection accuracy by adopting a DP matching scheme
  • Keywords
    authorisation; DP matching scheme; anomaly intrusion detection model; daemon processes; information profiles; intrusion technique database; misuse intrusion detection model; setuid programs; statistics; system call recording; user behavior analysis; Internet; Intrusion detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications and the Internet, 2002. (SAINT 2002). Proceedings. 2002 Symposium on
  • Conference_Location
    Nara
  • Print_ISBN
    0-7695-1447-2
  • Type

    conf

  • DOI
    10.1109/SAINT.2002.994455
  • Filename
    994455