Analyzing and evaluating dynamics in stide performance for intrusion detection

作者:

Highlights:

摘要

Anomaly-based intrusion detection (AID) techniques are useful for detecting novel intrusions into computing resources. One of simple but typical AID detectors proposed to date is stide, which is based on analysis of system call sequences. In this paper, we present a detailed formal framework to analyze, understand and improve the performance of stide and similar AID techniques. Several important properties of stide-like detectors are established through formal theorems, and validated by carefully conducted experiments using test datasets. Finally, the framework is utilized to reduce the cost of developing AID detectors by identifying the critical sections in the training dataset.

论文关键词:Intrusion detection,Computer security,Framework,Stide,System call

论文评审过程:Received 18 March 2005, Accepted 10 March 2006, Available online 27 June 2006.

论文官网地址:https://doi.org/10.1016/j.knosys.2006.03.008