DocumentCode
665554
Title
A host-based anomaly detection approach by representing system calls as states of kernel modules
Author
Murtaza, Syed Shariyar ; Khreich, Wael ; Hamou-Lhadj, Abdelwahab ; Couture, Mario
Author_Institution
Dept. of Electr. & Comput. Eng., Concordia Univ., Montreal, QC, Canada
fYear
2013
fDate
4-7 Nov. 2013
Firstpage
431
Lastpage
440
Abstract
Despite over two decades of research, high false alarm rates, large trace sizes and high processing times remain among the key issues in host-based anomaly intrusion detection systems. In an attempt to reduce the false alarm rate and processing time while increasing the detection rate, this paper presents a novel anomaly detection technique based on semantic interactions of system calls. The key concept is to represent system calls as states of kernel modules, analyze the state interactions, and identify anomalies by comparing the probabilities of occurrences of states in normal and anomalous traces. In addition, the proposed technique allows a visual understanding of system behaviour, and hence a more informed decision making. We evaluated this technique on Linux based programs of UNM datasets and a new modern Firefox dataset. We created the Firefox dataset on Linux using contemporary test suites and hacking techniques. The results show that our technique yields fewer false alarms and can handle large traces with smaller (or comparable) processing times compared against the existing techniques for the host based anomaly intrusion detection systems.
Keywords
Linux; probability; security of data; Firefox dataset; Linux based program; UNM datasets; anomalous trace; anomaly identification; contemporary test suites; hacking technique; host based anomaly intrusion detection approach; kernel module state; normal trace; state interaction analysis; state occurrence probability; system behaviour visual understanding; system call representation; system call semantic interaction; File systems; Hidden Markov models; Intrusion detection; Kernel; Linux; Training; Host-based Intrusion Detection System; Software Reliability; Software Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Reliability Engineering (ISSRE), 2013 IEEE 24th International Symposium on
Conference_Location
Pasadena, CA
Type
conf
DOI
10.1109/ISSRE.2013.6698896
Filename
6698896
Link To Document