A Dynamical System Approach to Intrusion Detection Using System Call Analysis
نویسندگان
چکیده
1 This research work was funded, in part, by an MRI grant from the National Science Foundation (Grant #: CNS – 0619069). ABSTRACT Code injections can aid successful intrusion attempts, thereby allowing viruses and worms to spread. Current research into intrusion detection is notably focused on application behavior profiling through system call trace analysis. Studying the system call layer has been identified as a potential approach to render revealing details about an application’s behavior. System call sequences available from the execution trace of an application can be subjected to different modeling techniques to approximate the application’s normal execution. This research views application programs as dynamical systems, and applies dynamical system analysis tools operating on time series data, merely the system calls made by an application, to identify the degree of determinism in a dynamical system. There is some prior work in the literature analyzing programs as dynamical systems, but they lack proper utilization of dynamical system formalisms and associated analysis tools. In our research we utilize a set of dynamical system analysis tools composed of Approximate Entropy, Central Tendency Measure, and Recurrence Plot derived measures. Our initial results are promising in detecting code injections.
منابع مشابه
A Hybrid Machine Learning Method for Intrusion Detection
Data security is an important area of concern for every computer system owner. An intrusion detection system is a device or software application that monitors a network or systems for malicious activity or policy violations. Already various techniques of artificial intelligence have been used for intrusion detection. The main challenge in this area is the running speed of the available implemen...
متن کاملA hybridization of evolutionary fuzzy systems and ant Colony optimization for intrusion detection
A hybrid approach for intrusion detection in computer networks is presented in this paper. The proposed approach combines an evolutionary-based fuzzy system with an Ant Colony Optimization procedure to generate high-quality fuzzy-classification rules. We applied our hybrid learning approach to network security and validated it using the DARPA KDD-Cup99 benchmark data set. The results indicate t...
متن کاملIntrusion Detection based on a Novel Hybrid Learning Approach
Information security and Intrusion Detection System (IDS) plays a critical role in the Internet. IDS is an essential tool for detecting different kinds of attacks in a network and maintaining data integrity, confidentiality and system availability against possible threats. In this paper, a hybrid approach towards achieving high performance is proposed. In fact, the important goal of this paper ...
متن کاملA New Intrusion Detection System to deal with Black Hole Attacks in Mobile Ad Hoc Networks
By extending wireless networks and because of their different nature, some attacks appear in these networks which did not exist in wired networks. Security is a serious challenge for actual implementation in wireless networks. Due to lack of the fixed infrastructure and also because of security holes in routing protocols in mobile ad hoc networks, these networks are not protected against attack...
متن کاملIntrusion Detection Using Evolutionary Hidden Markov Model
Intrusion detection systems are responsible for diagnosing and detecting any unauthorized use of the system, exploitation or destruction, which is able to prevent cyber-attacks using the network package analysis. one of the major challenges in the use of these tools is lack of educational patterns of attacks on the part of the engine analysis; engine failure that caused the complete training, ...
متن کامل