Behavioral Distance for Intrusion Detection

We introduce a notion, behavioral distance, for evaluating the extent to which processes—potentially running different programs and executing on different platforms—behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that cause...

全面介紹

Saved in:
書目詳細資料
Main Authors: GAO, Debin, Reiter, Michael K., SONG, Dawn
格式: text
語言:English
出版: Institutional Knowledge at Singapore Management University 2005
主題:
在線閱讀:https://ink.library.smu.edu.sg/sis_research/1243
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.113.7936
標簽: 添加標簽
沒有標簽, 成為第一個標記此記錄!
機構: Singapore Management University
語言: English
實物特徵
總結:We introduce a notion, behavioral distance, for evaluating the extent to which processes—potentially running different programs and executing on different platforms—behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead.