A real-time intrusion detection system based on learning program behavior

被引:0
|
作者
Ghosh, AK [1 ]
Michael, C [1 ]
Schatz, M [1 ]
机构
[1] Reliable Software Technol, Dulles, VA 20166 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In practice, most computer intrusions begin by misusing programs in clever ways to obtain unauthorized higher levels of privilege. One effective way to detect intrusive activity before system damage is perpetrated is to detect misuse of privileged programs in real-time. In this paper, we describe three machine learning algorithms that learn the normal behavior of programs running on the Solaris platform in order to detect unusual uses or misuses of these programs. The performance of the three algorithms has been evaluated by an independent laboratory in an off-line controlled evaluation against a set of computer intrusions and normal usage to determine rates of correct detection and false alarms. A real-time system has since been developed that will enable deployment of a program-based intrusion detection system in a real installation.
引用
收藏
页码:93 / 109
页数:17
相关论文
共 50 条
  • [1] Real-Time Network Intrusion Detection System Based on Deep Learning
    Dong, Yuansheng
    Wang, Rong
    He, Juan
    [J]. PROCEEDINGS OF 2019 IEEE 10TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2019), 2019, : 1 - 4
  • [2] Machine Learning Based Intrusion Detection System for Real-Time Smart Grid Security
    Sen, Puja
    Waghmare, Sumit
    [J]. APPEEC 2021: 2021 13TH IEEE PES ASIA PACIFIC POWER & ENERGY ENGINEERING CONFERENCE (APPEEC), 2021,
  • [3] Robust Real-time Intrusion Detection System
    Kim, Byung-Joo
    Kim, Il-Kon
    [J]. JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2005, 1 (01): : 9 - 13
  • [4] SwiftIDS: Real-time intrusion detection system based on LightGBM and parallel intrusion detection mechanism
    Jin, Dongzi
    Lu, Yiqin
    Qin, Jiancheng
    Cheng, Zhe
    Mao, Zhongshu
    [J]. COMPUTERS & SECURITY, 2020, 97
  • [5] A Real-time Intrusion Detection System Based on PSO-SVM
    Wang, Jun
    Hong, Xu
    Ren, Rong-rong
    Li, Tai-hang
    [J]. PROCEEDINGS OF 2009 INTERNATIONAL WORKSHOP ON INFORMATION SECURITY AND APPLICATION, 2009, : 319 - 321
  • [6] Deep Neural Network Based Real-Time Intrusion Detection System
    Sharuka Promodya Thirimanne
    Lasitha Jayawardana
    Lasith Yasakethu
    Pushpika Liyanaarachchi
    Chaminda Hewage
    [J]. SN Computer Science, 2022, 3 (2)
  • [7] Real-Time Hybrid Intrusion Detection System Using Machine Learning Techniques
    Dutt, Inadyuti
    Borah, Samarjeet
    Maitra, Indra Kanta
    Bhowmik, Kuharan
    Maity, Ayindrilla
    Das, Suvosmita
    [J]. ADVANCES IN COMMUNICATION, DEVICES AND NETWORKING, 2018, 462 : 885 - 894
  • [8] Real-time intrusion detection based on residual learning through ResNet algorithm
    Shaikh, Asma
    Gupta, Preeti
    [J]. INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2022,
  • [9] Real-Time Intrusion Detection in Power System Operations
    Valenzuela, Jorge
    Wang, Jianhui
    Bissinger, Nancy
    [J]. IEEE TRANSACTIONS ON POWER SYSTEMS, 2013, 28 (02) : 1052 - 1062
  • [10] Real-time sow behavior detection based on deep learning
    Zhang, Yuanqin
    Cai, Jiahao
    Xiao, Deqin
    Li, Zesen
    Xiong, Benhai
    [J]. COMPUTERS AND ELECTRONICS IN AGRICULTURE, 2019, 163