Title :
Host intrusion detection using system call argument-based clustering combined with Bayesian classification
Author :
Oualid Koucham;Tajjeeddine Rachidi;Nasser Assem
Author_Institution :
School of Science and Engineering, Al Akhawayn University in Ifrane, Ifrane 53000, Morocco
Abstract :
We deal in this paper with anomaly-based host intrusion detection using system call traces produced by a host´s kernel. In addition to the sequences, we leverage system call arguments, contextual information and domain level knowledge to produce clusters for each individual system call. These clusters are then used to rewrite process sequences of system calls obtained from kernel logs. The new sequences are then fed to a naïve Bayes supervised classifier (SC2.2) that builds class conditional probabilities from Markov modeling of system call sequences. The results of our proposed two-stage (that is clustering followed by classification) intrusion detection system on the 1999 DARPA dataset from the MIT Lincoln Lab show significant performance improvements in terms of false positive rate, while maintaining a high detection rate when compared with other classifiers. The two-stage classifier fares also better than classification alone with SC2.2 on system calls without arguments and contextual knowledge.
Keywords :
"Intrusion detection","Hidden Markov models","Measurement","Markov processes","Monitoring","Intelligent systems","Electronic mail"
Conference_Titel :
SAI Intelligent Systems Conference (IntelliSys), 2015
DOI :
10.1109/IntelliSys.2015.7361267