Behavioral Distance for Intrusion Detection

We introduce a notion, behavioral distance, for evaluating the extent to which processes—potentially running different programs and executing on different platforms—behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that cause...

Full description

Saved in:
Bibliographic Details
Main Authors: GAO, Debin, Reiter, Michael K., SONG, Dawn
Format: text
Language:English
Published: Institutional Knowledge at Singapore Management University 2005
Subjects:
Online Access:https://ink.library.smu.edu.sg/sis_research/1243
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.113.7936
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Singapore Management University
Language: English
id sg-smu-ink.sis_research-2242
record_format dspace
spelling sg-smu-ink.sis_research-22422010-12-22T08:24:06Z Behavioral Distance for Intrusion Detection GAO, Debin Reiter, Michael K. SONG, Dawn We introduce a notion, behavioral distance, for evaluating the extent to which processes—potentially running different programs and executing on different platforms—behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead. 2005-09-01T07:00:00Z text https://ink.library.smu.edu.sg/sis_research/1243 info:doi/10.1007/11663812_4 http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.113.7936 Research Collection School Of Computing and Information Systems eng Institutional Knowledge at Singapore Management University Information Security
institution Singapore Management University
building SMU Libraries
continent Asia
country Singapore
Singapore
content_provider SMU Libraries
collection InK@SMU
language English
topic Information Security
spellingShingle Information Security
GAO, Debin
Reiter, Michael K.
SONG, Dawn
Behavioral Distance for Intrusion Detection
description We introduce a notion, behavioral distance, for evaluating the extent to which processes—potentially running different programs and executing on different platforms—behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead.
format text
author GAO, Debin
Reiter, Michael K.
SONG, Dawn
author_facet GAO, Debin
Reiter, Michael K.
SONG, Dawn
author_sort GAO, Debin
title Behavioral Distance for Intrusion Detection
title_short Behavioral Distance for Intrusion Detection
title_full Behavioral Distance for Intrusion Detection
title_fullStr Behavioral Distance for Intrusion Detection
title_full_unstemmed Behavioral Distance for Intrusion Detection
title_sort behavioral distance for intrusion detection
publisher Institutional Knowledge at Singapore Management University
publishDate 2005
url https://ink.library.smu.edu.sg/sis_research/1243
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.113.7936
_version_ 1770570927530049536