DocumentCode
2885446
Title
Combining Hidden Markov Models for Improved Anomaly Detection
Author
Khreich, Wael ; Granger, Eric ; Sabourin, Robert ; Miri, Ali
Author_Institution
Lab. d´´Imagerie, de Vision et d´´Intell. Artificielle (LIVIA), Ecole de Technol. Super., Montreal, QC, Canada
fYear
2009
fDate
14-18 June 2009
Firstpage
1
Lastpage
6
Abstract
In host-based intrusion detection systems (HIDS), anomaly detection involves monitoring for significant deviations from normal system behavior. Hidden Markov Models (HMMs) have been shown to provide a high level performance for detecting anomalies in sequences of system calls to the operating system kernel. Although the number of hidden states is a critical parameter for HMM performance, it is often chosen heuristically or empirically, by selecting the single value that provides the best performance on training data. However, this single best HMM does not typically provide a high level of performance over the entire detection space. This paper presents a multiple-HMMs approach, where each HMM is trained using a different number of hidden states, and where HMM responses are combined in the receiver operating characteristics (ROC) space according to the maximum realizable ROC (MRROC) technique. The performance of this approach is compared favorably to that of a single best HMM and to a traditional sequence matching technique called STIDE, using different synthetic HIDS data sets. Results indicate that this approach provides a higher level of performance over a wide range of training set sizes with various alphabet sizes and irregularity indices, and different anomaly sizes, without a significant computational and storage overhead.
Keywords
hidden Markov models; operating system kernels; security of data; HIDS; HMM; anomaly detection; hidden Markov model; host-based intrusion detection system; maximum realizable ROC technique; operating system kernel; receiver operating characteristics; system call; Communications Society; Computerized monitoring; Event detection; Hidden Markov models; Information technology; Intrusion detection; Kernel; Operating systems; Paper technology; Training data;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2009. ICC '09. IEEE International Conference on
Conference_Location
Dresden
ISSN
1938-1883
Print_ISBN
978-1-4244-3435-0
Electronic_ISBN
1938-1883
Type
conf
DOI
10.1109/ICC.2009.5198832
Filename
5198832
Link To Document