DocumentCode
77174
Title
An OS-level Framework for Anomaly Detection in Complex Software Systems
Author
Bovenzi, Antonio ; Brancati, Francesco ; Russo, Stefano ; Bondavalli, Andrea
Author_Institution
Dipt. di Ing. Elettr. e delle Tecnol. dell´Inf., Univ. di Napoli Federico II, Naples, Italy
Volume
12
Issue
3
fYear
2015
fDate
May-June 1 2015
Firstpage
366
Lastpage
372
Abstract
Revealing anomalies at the operating system (OS) level to support online diagnosis activities of complex software systems is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) are inadequate or cannot be applied. In this paper we propose a configurable detection framework to reveal anomalies in the OS behavior, related to system misbehaviors. The detector is based on online statistical analyses techniques, and it is designed for systems that operate under variable and non-stationary conditions. The framework is evaluated to detect the activation of software faults in a complex distributed system for Air Traffic Management (ATM). Results of experiments with two different OSs, namely Linux Red Hat EL5 and Windows Server 2008, show that the detector is effective for mission-critical systems. The framework can be configured to select the monitored indicators so as to tune the level of intrusivity. A sensitivity analysis of the detector parameters is carried out to show their impact on the performance and to give to practitioners guidelines for its field tuning.
Keywords
operating systems (computers); software fault tolerance; statistical analysis; Linux Red Hat EL5; OS-level framework; Windows Server 2008; air traffic management; anomaly detection; complex distributed system; complex software systems; configurable detection framework; mission-critical systems; online statistical analysis techniques; operating system level; Detectors; Linux; Monitoring; Operating systems; Probes; Software systems; Anomaly-detection; mission-critical systems; operating system; system monitoring;
fLanguage
English
Journal_Title
Dependable and Secure Computing, IEEE Transactions on
Publisher
ieee
ISSN
1545-5971
Type
jour
DOI
10.1109/TDSC.2014.2334305
Filename
6847216
Link To Document