A Multi-Order Markov Chain Based Scheme for Anomaly Detection

被引:11
|
作者
Sha, Wenyao [1 ]
Zhu, Yongxin [1 ]
Huang, Tian [1 ]
Qiu, Meikang [2 ]
Zhu, Yan [1 ]
Zhang, Qiannan [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Microelect, Shanghai 200030, Peoples R China
[2] Univ Kentucky, Dept Elect & Comp Engn, Lexington, KY 40506 USA
关键词
Markov chain; Kth-order Markov chain; multivariate time series; anomaly detection; COMPUTER AUDIT DATA; INTRUSION-DETECTION; MODEL;
D O I
10.1109/COMPSACW.2013.12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a feasible multi-order Markov chain based scheme for anomaly detection in server systems. In our approach, both the high-order Markov chain and multivariate time series are taken into account, along with the detailed design of training and testing algorithms. To evaluate its effectiveness, the Defense Advanced Research Projects Agency (DARPA) Intrusion Detection Evaluation Data Set is used as stimuli to our model, by which system calls and the corresponding return values form a two-dimensional input set. The calculation result shows that this approach is able to produce several effective indicators of anomalies. In addition to the absolute values given by an individual single-order model, we also notice a novelty unprecedented before, i.e., the changes in ranking positions of outputs from different-order ones also correlate closely with abnormal behaviours. Moreover, the analysis and application proves our approach's efficiency in consuming reasonable cost of time and storage.
引用
收藏
页码:83 / 88
页数:6
相关论文
共 50 条
  • [41] A Pre-Training Framework Based on Multi-Order Acoustic Simulation for Replay Voice Spoofing Detection
    Go, Changhwan
    Park, Nam In
    Jeon, Oc-Yeub
    Chun, Chanjun
    SENSORS, 2023, 23 (16)
  • [42] Image Matching with Multi-order Features
    Li, Yujian
    Zeng, Shaofeng
    Yang, Yong
    IEEE SIGNAL PROCESSING LETTERS, 2015, 22 (12) : 2214 - 2218
  • [43] Hidden Markov Model Based Anomaly Intrusion Detection
    Jain, Ruchi
    Abouzakhar, Nasser S.
    2012 INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS, 2012, : 528 - 533
  • [44] Masquerade detection based on shell commands and high-order Markov chain models
    Xiao, Xi
    Zhai, Qi-Bin
    Tian, Xin-Guang
    Chen, Xiao-Juan
    Ye, Run-Guo
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2011, 39 (05): : 1199 - 1204
  • [45] Markov Chain-Based Feature Extraction for Anomaly Detection in Time Series and Its Industrial Application
    Zang, Dong
    Liu, Jinhai
    Wang, Huaizhen
    PROCEEDINGS OF THE 30TH CHINESE CONTROL AND DECISION CONFERENCE (2018 CCDC), 2018, : 1059 - 1063
  • [46] Laguerre-based parametric order reduction for parametric systems by multi-order Arnoldi
    Yuan, Jia-Wei
    Jiang, Yao-Lin
    Qi, Zhen-Zhong
    ASIAN JOURNAL OF CONTROL, 2022, 24 (06) : 3394 - 3407
  • [47] A Multi-Step Multi-Order Numerical Difference Method for Traveling Ionospheric Disturbances Detection
    Tang, Long
    Zhang, Xiaohong
    CHINA SATELLITE NAVIGATION CONFERENCE (CSNC) 2014 PROCEEDINGS, VOL II, 2014, 304 : 331 - 340
  • [48] Intensive Multi-order Feature Extraction for Incipient Fault Detection of Inverter System
    Wang, Min
    Cheng, Feiyang
    Xie, Min
    Qiu, Gen
    Zhang, Jingxin
    IEEE Transactions on Power Electronics, 2024,
  • [49] Biologically-inspired model for multi-order coloring texture boundary detection
    Chen, Tianding
    2006 IEEE International Conference on Information Acquisition, Vols 1 and 2, Conference Proceedings, 2006, : 183 - 188
  • [50] Magnetic field sensing based on multi-order resonances of atomic spins
    Yang, Hongying
    Wang, Qian
    Zhao, Binbin
    Li, Lin
    Zhai, Yueyang
    Han, Bangcheng
    Tang, Feng
    OPTICS EXPRESS, 2022, 30 (05) : 6618 - 6629