کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
461743 696628 2012 9 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A variable-length model for masquerade detection
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
A variable-length model for masquerade detection
چکیده انگلیسی

Masquerade detection is now one of the major concerns of system security research and its difficulty is to model user behavior on the nonstationary audit data. Many previous works represent the user behavior based on fixed-length models. In this paper, we propose a variable-length model to overcome their weakness in the precision and adaptability of user profiling. In the model, the user's normal behavior is profiled by Markov chain with states of variable-length sequences. At first multiple shell command streams of different lengths are generated and different shell command sequences are hierarchically merged into several sets to form the library of general sequences. Then the variable-length behavioral patterns of a valid user are mined and the Markov chain is constructed. While performing detection, the probabilities of short state sequences are calculated, smoothed with sliding windows, and finally used to classify the monitored user's activity as normal or abnormal. Our experiments with standard datasets such as Purdue data and SEA data reveal that the proposed model can achieve higher detection accuracy, require less memory and take shorter time than the other traditional methods and is amenable for real-time intrusion detection.


► A variable-length model is proposed to overcome the weakness of fixed models in the precision and adaptability of user profiling.
► In the model, the user's normal behavior is profiled by Markov chain with states of variable-length sequences.
► The model can achieve higher detection accuracy, require less memory and take shorter time than the other traditional methods.
► The model is amenable for real-time intrusion detection.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Systems and Software - Volume 85, Issue 11, November 2012, Pages 2470–2478
نویسندگان
, , , ,