Behavioral distance for intrusion detection

38Citations
Citations of this article
43Readers
Mendeley users who have this article in their library.
Get full text

Abstract

We introduce a notion, behavioral distance, for evaluating the extent to which processes - potentially running different programs and executing on different platforms - behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead. © Springer-Verlag Berlin Heidelberg 2006.

Cite

CITATION STYLE

APA

Gao, D., Reiter, M. K., & Song, D. (2006). Behavioral distance for intrusion detection. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 3858 LNCS, pp. 63–81). Springer Verlag. https://doi.org/10.1007/11663812_4

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free