DocumentCode
259718
Title
An abnormal file access behavior detection approach based on file path diversity
Author
Xiaobin Wang ; Yonglin Sun ; Yongjun Wang
Author_Institution
College of Computer, National University of Defense Technology, 410073, Changsha, HuNan Province, China
fYear
2014
fDate
15-17 May 2014
Firstpage
1
Lastpage
5
Abstract
Information security is a great challenge for organizations in our modern information world. Existing security facilities like Firewalls, Intrusion Detection Systems and Antivirus are not enough to guarantee the security of information. File is an important carrier of information, which is the intent of quite a number of attackers, in this paper, we propose an FPD-based approach for detecting abnormal file access behaviours. FPD (File Path Diversity) is a quantized value which measures how far a set of file paths is spread out, and in which abnormal file access behaviours and normal ones show significant differences, making it an effective indicator for detecting malicious processes that controlled by attackers to search and steal valuable files. An algorithm of calculating FPD values is presented, as well as a prototype system based on FPD for detecting malicious processes. Experiments demonstrate that FPD is very effective in detecting malicious processes with abnormal file access behaviours, we get a best result of a100% Detection Rate and a 3.85% False Positive Rate.
Keywords
Information security; abnormal file access behaviours; anomaly detection; file path diversity;
fLanguage
English
Publisher
iet
Conference_Titel
Information and Communications Technologies (ICT 2014), 2014 International Conference on
Conference_Location
Nanjing, China
Type
conf
DOI
10.1049/cp.2014.0632
Filename
6913685
Link To Document