A Multi-Order Markov Chain Based Scheme for Anomaly Detection

被引:11
|
作者
Sha, Wenyao [1 ]
Zhu, Yongxin [1 ]
Huang, Tian [1 ]
Qiu, Meikang [2 ]
Zhu, Yan [1 ]
Zhang, Qiannan [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Microelect, Shanghai 200030, Peoples R China
[2] Univ Kentucky, Dept Elect & Comp Engn, Lexington, KY 40506 USA
关键词
Markov chain; Kth-order Markov chain; multivariate time series; anomaly detection; COMPUTER AUDIT DATA; INTRUSION-DETECTION; MODEL;
D O I
10.1109/COMPSACW.2013.12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a feasible multi-order Markov chain based scheme for anomaly detection in server systems. In our approach, both the high-order Markov chain and multivariate time series are taken into account, along with the detailed design of training and testing algorithms. To evaluate its effectiveness, the Defense Advanced Research Projects Agency (DARPA) Intrusion Detection Evaluation Data Set is used as stimuli to our model, by which system calls and the corresponding return values form a two-dimensional input set. The calculation result shows that this approach is able to produce several effective indicators of anomalies. In addition to the absolute values given by an individual single-order model, we also notice a novelty unprecedented before, i.e., the changes in ranking positions of outputs from different-order ones also correlate closely with abnormal behaviours. Moreover, the analysis and application proves our approach's efficiency in consuming reasonable cost of time and storage.
引用
收藏
页码:83 / 88
页数:6
相关论文
共 50 条
  • [1] Statistical Learning for Anomaly Detection in Cloud Server Systems: A Multi-Order Markov Chain Framework
    Sha, Wenyao
    Zhu, Yongxin
    Chen, Min
    Huang, Tian
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2018, 6 (02) : 401 - 413
  • [2] Modelling rain risk: a multi-order Markov chain model approach
    Stowasser, Markus
    JOURNAL OF RISK FINANCE, 2011, 13 (01) : 45 - 60
  • [3] Summarizing and Quantifying Multilocus Linkage Disequilibrium Patterns with Multi-Order Markov Chain Models
    Feng, Sheng
    Wang, Shengchu
    JOURNAL OF BIOPHARMACEUTICAL STATISTICS, 2010, 20 (02) : 441 - 453
  • [4] Drone Detection Based on Multi-order Kinematic Parameters
    Liu, Sun-Xiang-Yu
    Li, Gui-Tao
    Zhan, Ya-Feng
    Gao, Peng
    Zidonghua Xuebao/Acta Automatica Sinica, 2022, 48 (06): : 1429 - 1447
  • [5] Sequence Comparison using Multi-Order Markov Chains
    Fang, Xiang
    Lu, Guoqing
    Zhang, Shunpu
    2010 4TH INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICAL ENGINEERING (ICBBE 2010), 2010,
  • [6] Hybrid Seismic Inversion Based on Multi-Order Anisotropic Markov Random Field
    Guo, Qiang
    Zhang, Hongbing
    Cao, Haitao
    Xiao, Wei
    Han, Feilong
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2020, 58 (01): : 407 - 420
  • [7] Position Prediction Social-relationship-based Of Multi-Order Markov Model
    Zou, Yue
    Zhang, SanFeng
    2015 THIRD INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA, 2015, : 36 - 43
  • [8] A Task Group Based Multi-order Critical Chain Identification Algorithm
    Liu, Qiong
    Liu, Na
    Ullah, Saif
    2009 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT, VOLS 1-4, 2009, : 1494 - 1498
  • [9] A Method to Estimate the Multimedia Communication Bands Based upon Multi-Order Markov Model
    Kojima, Tetsuya
    Enkhtur, Lkhamsuren
    Fujiwara, Akiko
    Aono, Masahiro
    JOURNAL OF ADVANCED COMPUTATIONAL INTELLIGENCE AND INTELLIGENT INFORMATICS, 2007, 11 (06) : 655 - 661
  • [10] Multi-Order Networks for Action Unit Detection
    Tallec, Gauthier
    Dapogny, Arnaud
    Bailly, Kevin
    IEEE TRANSACTIONS ON AFFECTIVE COMPUTING, 2023, 14 (04) : 2876 - 2888