Skip to main navigation Skip to search Skip to main content

An intrusion detection method based on system call temporal serial analysis

  • Shi Pu*
  • , Bo Lang
  • *Corresponding author for this work
  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

System call sequences are useful criteria to judge the behaviors of processes. How to generate an efficient matching algorithm and how to build up an implementable system are two of the most difficult problems. In this paper, we explore the possibility of extending consecutive system call to incorporate temporal signature to the Host-based Intrusion Detection System. In this model, we use the real-time detected system call sequences and their consecutive time interval as the data source, and use temporal signature to filter the real model. During the monitoring procedure, we use data mining methods to analyze the source dynamically and implement incremental learning mechanism. Through studying small size samples and incremental learning, the detecting ability of the system can be still good when the sample's size is small. This paper also introduces the key technologies to build such a system, and verifies this intrusion detection method in real time environment. Finally, this paper gives the experiments results to verify the availability and efficiency of our system.

Original languageEnglish
Title of host publicationAdvanced Intelligent Computing Theories and Applications
Subtitle of host publicationWith Aspects of Theoretical and Methodological Issues - Third International Conference on Intelligent Computing, ICIC 2007, Proceedings
PublisherSpringer Verlag
Pages656-666
Number of pages11
ISBN (Print)9783540741701
DOIs
StatePublished - 2007
Event3rd International Conference on Intelligent Computing, ICIC 2007 - Qingdao, China
Duration: 21 Aug 200724 Aug 2007

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4681 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference3rd International Conference on Intelligent Computing, ICIC 2007
Country/TerritoryChina
CityQingdao
Period21/08/0724/08/07

Fingerprint

Dive into the research topics of 'An intrusion detection method based on system call temporal serial analysis'. Together they form a unique fingerprint.

Cite this