%0 Journal Article %T Novel Method for Anomaly Detection of User Behavior Based on Shell Commands and DTMC Models
基于Shell命令和DTMC模型的用户行为异常检测新方法 %A XIAO Xi %A ZHAI Qi-bin %A TIAN Xin-guang %A CHEN Xiao-juan %A
肖喜 %A 翟起滨 %A 田新广 %A 陈小娟 %J 计算机科学 %D 2011 %I %X This paper presented a novel method for anomaly detection of user behavior based on the discretctime Markov chain model,which is applicable to intrusion detection systems using shell commands as audit data. In the training period, the uncertainty of the user's behavior and the relevance of the operation of shell commands in short time were fully considered. This method takes the sequences of shell commands as the basic processing units. It merges the sequences into sets in terms of their ordered frequencies and then constructs states of the Markov chain on the merged resups. Therefore this method increases the accuracy of describing the normal behavior profile and the adaptability to the variations of the user's behavior and sharply reduces the number of states and the required storage space. In the detection stage, considering the real-time performance and the accuracy requirement of the detection system, it analyzes the anomaly degree of the user's behavior by computing the occurrence probabilities of the state sequences, and then provides two schemes, based on the probability stream filtered with single window or multi windows, to classify the user's behavior. I}he results of our experiments show that this method can achieve higher detection performance and practicability than others. %K Network security %K Intrusion detection %K Shell command %K Anomaly detection %K Discretctime Markov chain
网络安全,入侵检测 %K shell命令,异常检测,离散时间Markov链 %U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=64A12D73428C8B8DBFB978D04DFEB3C1&aid=17DDCED190714E79FAEB836CCC3094BB&yid=9377ED8094509821&vid=16D8618C6164A3ED&iid=708DD6B15D2464E8&sid=318E4CC20AED4940&eid=BC93E897A01F4B8B&journal_id=1002-137X&journal_name=计算机科学&referenced_num=0&reference_num=0