Motif-oriented representation of sequences for a host-based intrusion detection system

0Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Audit sequences have been used effectively to study process behaviors and build host-based intrusion detection models. Most sequencebased techniques make use of a pre-defined window size for scanning the sequences to model process behavior. In this paper, we propose two methods for extracting variable length patterns from audit sequences that avoid the necessity of such a pre-determined parameter. We also present a technique for abstract representation of the sequences, based on the empirically determined variable length patterns within die audit sequence, and explore the usage of such representation for detecting anomalies in sequences. Our methodology for anomaly detection takes two factors into account: the presence of individual malicious motifs, and the spatial relationships between the motifs that are present in a sequence. Thus, our method subsumes most of the past works, which primarily based on only the first factor. The preliminary experimental observations appear to be quite encouraging.

Cite

CITATION STYLE

APA

Tandon, G., Mitra, D., & Chan, P. K. (2004). Motif-oriented representation of sequences for a host-based intrusion detection system. In Lecture Notes in Artificial Intelligence (Subseries of Lecture Notes in Computer Science) (Vol. 3029, pp. 605–615). Springer Verlag. https://doi.org/10.1007/978-3-540-24677-0_62

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free