• DocumentCode
    2885446
  • Title

    Combining Hidden Markov Models for Improved Anomaly Detection

  • Author

    Khreich, Wael ; Granger, Eric ; Sabourin, Robert ; Miri, Ali

  • Author_Institution
    Lab. d´´Imagerie, de Vision et d´´Intell. Artificielle (LIVIA), Ecole de Technol. Super., Montreal, QC, Canada
  • fYear
    2009
  • fDate
    14-18 June 2009
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    In host-based intrusion detection systems (HIDS), anomaly detection involves monitoring for significant deviations from normal system behavior. Hidden Markov Models (HMMs) have been shown to provide a high level performance for detecting anomalies in sequences of system calls to the operating system kernel. Although the number of hidden states is a critical parameter for HMM performance, it is often chosen heuristically or empirically, by selecting the single value that provides the best performance on training data. However, this single best HMM does not typically provide a high level of performance over the entire detection space. This paper presents a multiple-HMMs approach, where each HMM is trained using a different number of hidden states, and where HMM responses are combined in the receiver operating characteristics (ROC) space according to the maximum realizable ROC (MRROC) technique. The performance of this approach is compared favorably to that of a single best HMM and to a traditional sequence matching technique called STIDE, using different synthetic HIDS data sets. Results indicate that this approach provides a higher level of performance over a wide range of training set sizes with various alphabet sizes and irregularity indices, and different anomaly sizes, without a significant computational and storage overhead.
  • Keywords
    hidden Markov models; operating system kernels; security of data; HIDS; HMM; anomaly detection; hidden Markov model; host-based intrusion detection system; maximum realizable ROC technique; operating system kernel; receiver operating characteristics; system call; Communications Society; Computerized monitoring; Event detection; Hidden Markov models; Information technology; Intrusion detection; Kernel; Operating systems; Paper technology; Training data;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2009. ICC '09. IEEE International Conference on
  • Conference_Location
    Dresden
  • ISSN
    1938-1883
  • Print_ISBN
    978-1-4244-3435-0
  • Electronic_ISBN
    1938-1883
  • Type

    conf

  • DOI
    10.1109/ICC.2009.5198832
  • Filename
    5198832