skip to main content
10.1145/3264437.3264486acmotherconferencesArticle/Chapter ViewAbstractPublication PagessinConference Proceedingsconference-collections
short-paper

Towards Profiling Program Instances in Host-Based Intrusion Detection Systems by Recognizing Software Update Patterns

Published: 10 September 2018 Publication History

Abstract

Host intrusion detection systems are used to analyze internal events on host machines and detect behavioral patterns that differ from normal operation of the system and its processes. One important aspect in observing the behavior of processes are the application updates that may change the behavior of an application but also potentially help to build a profile for the application when observing its update patterns. In this study, we observe update frequencies and patterns of a set of applications on 100 machines during an analysis period of 100 days. Our preliminary results indicate that it is possible to detect clear software update patterns that can be used for profiling processes.

References

[1]
Omar Al-Jarrah and Ahmad Arafat. 2014. Network Intrusion Detection System using attack behavior classification. In 5th International Conference on Information and Communication Systems (ICICS), 2014. IEEE, 1--6.
[2]
H. Alanazi, R. Noor, B. Zaidan, and A. Zaidan. 2010. Intrusion detection system: overview. arXiv preprint arXiv:1002.4047 (2010).
[3]
J. Hu, X. Yu, D. Qiu, and H. H. Chen. 2009. A simple and efficient hidden Markov model scheme for host-based anomaly intrusion detection. IEEE Network 23, 1 (2009), 42--47.
[4]
Richard A Kemmerer and Giovanni Vigna. 2002. Intrusion detection: a brief history and overview. Computer 35, 4 (2002), supl27--supl30.
[5]
Microsoft. 2018. Deploy updates using Windows Update for Business. https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb. (2018).

Index Terms

  1. Towards Profiling Program Instances in Host-Based Intrusion Detection Systems by Recognizing Software Update Patterns

      Recommendations

      Comments

      Information & Contributors

      Information

      Published In

      cover image ACM Other conferences
      SIN '18: Proceedings of the 11th International Conference on Security of Information and Networks
      September 2018
      148 pages
      ISBN:9781450366083
      DOI:10.1145/3264437
      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      In-Cooperation

      • Cardiff University: Cardiff University

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      Published: 10 September 2018

      Permissions

      Request permissions for this article.

      Check for updates

      Author Tags

      1. Intrusion detection
      2. host intrusion detection systems
      3. software updates

      Qualifiers

      • Short-paper
      • Research
      • Refereed limited

      Conference

      SIN '18

      Acceptance Rates

      SIN '18 Paper Acceptance Rate 24 of 42 submissions, 57%;
      Overall Acceptance Rate 102 of 289 submissions, 35%

      Contributors

      Other Metrics

      Bibliometrics & Citations

      Bibliometrics

      Article Metrics

      • 0
        Total Citations
      • 64
        Total Downloads
      • Downloads (Last 12 months)0
      • Downloads (Last 6 weeks)0
      Reflects downloads up to 08 Mar 2025

      Other Metrics

      Citations

      View Options

      Login options

      View options

      PDF

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader

      Figures

      Tables

      Media

      Share

      Share

      Share this Publication link

      Share on social media