A Multi-Order Markov Chain Based Scheme for Anomaly Detection

被引:11
|
作者
Sha, Wenyao [1 ]
Zhu, Yongxin [1 ]
Huang, Tian [1 ]
Qiu, Meikang [2 ]
Zhu, Yan [1 ]
Zhang, Qiannan [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Microelect, Shanghai 200030, Peoples R China
[2] Univ Kentucky, Dept Elect & Comp Engn, Lexington, KY 40506 USA
关键词
Markov chain; Kth-order Markov chain; multivariate time series; anomaly detection; COMPUTER AUDIT DATA; INTRUSION-DETECTION; MODEL;
D O I
10.1109/COMPSACW.2013.12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a feasible multi-order Markov chain based scheme for anomaly detection in server systems. In our approach, both the high-order Markov chain and multivariate time series are taken into account, along with the detailed design of training and testing algorithms. To evaluate its effectiveness, the Defense Advanced Research Projects Agency (DARPA) Intrusion Detection Evaluation Data Set is used as stimuli to our model, by which system calls and the corresponding return values form a two-dimensional input set. The calculation result shows that this approach is able to produce several effective indicators of anomalies. In addition to the absolute values given by an individual single-order model, we also notice a novelty unprecedented before, i.e., the changes in ranking positions of outputs from different-order ones also correlate closely with abnormal behaviours. Moreover, the analysis and application proves our approach's efficiency in consuming reasonable cost of time and storage.
引用
收藏
页码:83 / 88
页数:6
相关论文
共 50 条
  • [21] Event Detection with Multi-Order Graph Convolution and Aggregated Attention
    Yan, Haoran
    Jin, Xiaolong
    Meng, Xiangbin
    Guo, Jiafeng
    Cheng, Xueqi
    2019 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING AND THE 9TH INTERNATIONAL JOINT CONFERENCE ON NATURAL LANGUAGE PROCESSING (EMNLP-IJCNLP 2019): PROCEEDINGS OF THE CONFERENCE, 2019, : 5766 - 5770
  • [22] Research on Markov chain model for system call anomaly detection
    Qian, Q
    Wang, XF
    PROCEEDINGS OF THE 8TH JOINT CONFERENCE ON INFORMATION SCIENCES, VOLS 1-3, 2005, : 328 - 333
  • [23] Anomaly Detection Algorithm in ICS Based on Mixed-Order Markov Tree Model
    Zhang R.-B.
    Wu P.
    Lu Y.
    Guo Z.-Y.
    Wu, Pei (dorademon@163.com), 1600, Science Press (46): : 127 - 141
  • [24] Markov Chain Model Based on Cameron's CTD Ship Detection Scheme
    Kouroupis, Georgios
    Anastassopoulos, Vassilis
    2016 IEEE INTERNATIONAL CONFERENCE ON IMAGING SYSTEMS AND TECHNIQUES (IST), 2016, : 100 - 105
  • [25] MULTI-ORDER MICRODIFFUSION ANALYSIS
    ISHIHARA, H
    ISHIZAKA, O
    CHEMICAL & PHARMACEUTICAL BULLETIN, 1968, 16 (12) : 2524 - +
  • [26] Multi-order cancellation technology
    Li, FXH
    Corsetto, G
    MICROWAVE JOURNAL, 1997, 40 (10) : 84 - &
  • [27] The coming multi-order world
    Flockhart, Trine
    CONTEMPORARY SECURITY POLICY, 2016, 37 (01) : 3 - 30
  • [28] Multivariate Multi-Order Markov Multi-Modal Prediction With Its Applications in Network Traffic Management
    Liu, Huazhong
    Yang, Laurence T.
    Chen, Jinjun
    Ye, Minghao
    Ding, Jihong
    Kuang, Liwei
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2019, 16 (03): : 828 - 841
  • [29] Anomaly detection based on a granular Markov model
    Zhou, Yanjun
    Ren, Huorong
    Li, Zhiwu
    Pedrycz, Witold
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 187
  • [30] Anomaly detection based on a dynamic Markov model
    Ren, Huorong
    Ye, Zhixing
    Li, Zhiwu
    INFORMATION SCIENCES, 2017, 411 : 52 - 65