Computer Science ›› 2010, Vol. 37 ›› Issue (3): 86-90.

Previous Articles     Next Articles

Research on Program Behavior Model and Anomaly Detection Based on Multiple Abstraction

CHENG Xia,WANG Xiao-feng   

  • Online:2018-12-01 Published:2018-12-01

Abstract: Efficient short sequence models used in anomaly analysis of program behaviors arc not available in anomaly detection field. The current models are short of abstracting program behaviors. Therefore, a new highly self-explanatory pattern called GV pattern(gapped variable frequent pattern) was provided to cover three fundamental structures of program:sequence, selection and circulation. Subsequently, GV pattern mined algorithm and system-call flow chart model based on GV pattern library were presented in details. Experiments show that the anomaly detection algorithm based on new model keeps low detection overhead and false positive rate on the condition of high detection rate, which is crucial in a real-time intrusion detection system.

Key words: Anomaly detection, Short sequence model, l3chavior analysis, Pattern matching, Data mining

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!