On Gray-Box Program Tracking for Anomaly Detection

Many host-based anomaly detection systems monitor a process ostensibly running a known program by observing the system calls the process makes. Numerous improvements to the precision of this approach have been proposed, such as tracking system call sequences, and various "gray-box" extensi...

Full description

Saved in:
Bibliographic Details
Main Authors: GAO, Debin, Reiter, Michael K., SONG, Dawn
Format: text
Language:English
Published: Institutional Knowledge at Singapore Management University 2004
Subjects:
Online Access:https://ink.library.smu.edu.sg/sis_research/1241
http://dl.acm.org/citation.cfm?id=1251383
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Singapore Management University
Language: English