全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

Novel Method for Anomaly Detection of User Behavior Based on Shell Commands and DTMC Models
基于Shell命令和DTMC模型的用户行为异常检测新方法

Keywords: Network security,Intrusion detection,Shell command,Anomaly detection,Discretctime Markov chain
网络安全,入侵检测
,shell命令,异常检测,离散时间Markov链

Full-Text   Cite this paper   Add to My Lib

Abstract:

This paper presented a novel method for anomaly detection of user behavior based on the discretctime Markov chain model,which is applicable to intrusion detection systems using shell commands as audit data. In the training period, the uncertainty of the user's behavior and the relevance of the operation of shell commands in short time were fully considered. This method takes the sequences of shell commands as the basic processing units. It merges the sequences into sets in terms of their ordered frequencies and then constructs states of the Markov chain on the merged resups. Therefore this method increases the accuracy of describing the normal behavior profile and the adaptability to the variations of the user's behavior and sharply reduces the number of states and the required storage space. In the detection stage, considering the real-time performance and the accuracy requirement of the detection system, it analyzes the anomaly degree of the user's behavior by computing the occurrence probabilities of the state sequences, and then provides two schemes, based on the probability stream filtered with single window or multi windows, to classify the user's behavior. I}he results of our experiments show that this method can achieve higher detection performance and practicability than others.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133