Towards Reliable Data Feature Retrieval And Decision Engine In Host-Based Anomaly Detection Systems

PROCEEDINGS OF THE 2015 10TH IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS(2015)

引用 21|浏览13
暂无评分
摘要
Host-based anomaly detection systems (HADS) serves as the second line of defense after cyber attacks have penetrated the network level defense. The major components of reliable HADS includes enriched data source (DS), computational efficient data feature retrieval (DFR), accurate and fast decision engine (DE). ADFA-LD is a recently published data set which reflects the invisible threat environment of modern computer system. The existing HADS utilizing ADFA-LD as DS, exhibits high computational DFR and inferior performance of the DE at real-time. The major drawback is inability to acquire representative features from host activities. Confronting this drawback in this paper, at DFR a character data zero watermark inspired statistical based strategy is developed for integer data to extract hidden reliable or representative features from system calls of the trace. At DE, three supervised machine learning classifiers such as support vector machine (SVM) with linear and radial bases function (RBF) kernels and k-nearest neighbor (KNN) are evaluated across detection rate (DR), false alarm rate (FAR) and computational time. The numerical trials validates that the suggested statistical feature extraction strategy at DFR and KNN at DE can attain acceptable performance at real-time
更多
查看译文
关键词
Host based intrusion detection systems (HIDS),System calls,Zero-day attacks,Low foot print attacks
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要