Loading [a11y]/accessibility-menu.js
An improved Hidden Markov Model for anomaly detection using frequent common patterns | IEEE Conference Publication | IEEE Xplore

An improved Hidden Markov Model for anomaly detection using frequent common patterns


Abstract:

Host-based intrusion detection techniques are needed to ensure the safety and security of software systems, especially, if these systems handle sensitive data. Most host-...Show More

Abstract:

Host-based intrusion detection techniques are needed to ensure the safety and security of software systems, especially, if these systems handle sensitive data. Most host-based intrusion detection systems involve building some sort of reference models offline, usually from execution traces (in the absence of the source code), to characterize the system healthy behavior. The models can later be used as a baseline for online detection of abnormal behavior. Perhaps the most popular techniques are the ones based on the use of Hidden Markov Models (HMM). These techniques, however, require long training time of the models, which makes them computationally infeasible, the main reason being the large size of typical traces. In this paper, we propose an improved HMM using the concept of frequent common patterns. In other words, we build models based on extracting the largest n-grams (patterns) in the traces instead of taking each trace event on its own. We show through a case study that our approach can reduce the training time by 31.96%-48.44% compared to the original HMM algorithms while keeping almost the same accuracy rate.
Date of Conference: 10-15 June 2012
Date Added to IEEE Xplore: 29 November 2012
ISBN Information:

ISSN Information:

Conference Location: Ottawa, ON, Canada

Contact IEEE to Subscribe

References

References is not available for this document.