Fuzzy Intrusion Detection System via Data Mining Technique With Sequences of System Calls
There are two main approaches for implementing IDS; host based and network based. While the former is implemented in the form of software deployed on a host, the latter, usually is built as a hardware product with its own hardware platform (IDS appliance). In this paper, a host based intrusion detection system, that uses the idea of tracing system calls, is introduced. As a program runs, it uses the services of the underlying operating system to do some system calls. This system does not exactly need to know the program codes of each process. Normal and intrusive behaviors are collected with gathering the sequences of system calls for each process. Analysis of data is done via data mining and fuzzy techniques. Data mining is used to extract the normal behavior. The proposed system is shown to improve the performance, and decrease size of database, time complexity, and the rate of false alarms.
Process-based Intrusion Detection Data mining Fuzzy Operating system system calls kernel
Mohammad Akbarpour Sekeh Mohd.Aizaini bin Maarof
Department of Computer System and Communication Faculty of Computer Science and Information,UTM Skudai,Malaysia
国际会议
The Fifth International Conference on Information Assurance and Security(第五届信息保障与安全国际会议)
西安
英文
154-157
2009-08-18(万方平台首次上网日期,不代表论文的发表时间)