An OS-level Framework for Anomaly Detection in Complex Software Systems

被引:17
|
作者
Bovenzi, Antonio [1 ]
Brancati, Francesco [2 ]
Russo, Stefano [1 ]
Bondavalli, Andrea [3 ]
机构
[1] Univ Naples Federico II, Dipartimento Ingn Elettr & Tecnol Informaz, Naples, Italy
[2] Resiltech SRL, Pontedera, PI, Italy
[3] Univ Florence, Dipartimento Sistemi & Informat, I-50121 Florence, Italy
关键词
Anomaly-detection; system monitoring; operating system; mission-critical systems;
D O I
10.1109/TDSC.2014.2334305
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Revealing anomalies at the operating system (OS) level to support online diagnosis activities of complex software systems is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) are inadequate or cannot be applied. In this paper we propose a configurable detection framework to reveal anomalies in the OS behavior, related to system misbehaviors. The detector is based on online statistical analyses techniques, and it is designed for systems that operate under variable and non-stationary conditions. The framework is evaluated to detect the activation of software faults in a complex distributed system for Air Traffic Management (ATM). Results of experiments with two different OSs, namely Linux Red Hat EL5 and Windows Server 2008, show that the detector is effective for mission-critical systems. The framework can be configured to select the monitored indicators so as to tune the level of intrusivity. A sensitivity analysis of the detector parameters is carried out to show their impact on the performance and to give to practitioners guidelines for its field tuning.
引用
收藏
页码:366 / 372
页数:7
相关论文
共 50 条
  • [11] Exploiting OS-level mechanisms to implement mobile code security
    Felmetsger, V
    Vigna, G
    ICECCS 2005: 10TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS, PROCEEDINGS, 2005, : 234 - 243
  • [12] MultiLanes: Providing Virtualized Storage for OS-Level Virtualization on Manycores
    Kang, Junbin
    Hu, Chunming
    Wo, Tianyu
    Zhai, Ye
    Zhang, Benlong
    Huai, Jinpeng
    ACM TRANSACTIONS ON STORAGE, 2016, 12 (03)
  • [13] LFOC plus : A Fair OS-Level Cache-Clustering Policy for Commodity Multicore Systems
    Saez, Juan Carlos
    Castro, Fernando
    Fanizzi, Graziano
    Prieto-Matias, Manuel
    IEEE TRANSACTIONS ON COMPUTERS, 2021, 71 (08) : 1952 - 1967
  • [14] OS-level power consumption estimator for multimedia mobile devices
    Tang, Q.
    Groba, A. M.
    Blazquez, E.
    Juarez, E.
    2015 IEEE INTERNATIONAL SYMPOSIUM ON CONSUMER ELECTRONICS (ISCE), 2015,
  • [15] Exploiting OS-Level Memory Offlining for DRAM Power Management
    Lee, Seunghak
    Kim, Nam Sung
    Kim, Daehoon
    IEEE COMPUTER ARCHITECTURE LETTERS, 2019, 18 (02) : 141 - 144
  • [16] Facilitating Inter-Application Interactions for OS-level Virtualization
    Shan, Zhiyong
    Wang, Xin
    Chiueh, Tzi-cker
    Meng, Xiaofeng
    ACM SIGPLAN NOTICES, 2012, 47 (07) : 75 - 86
  • [17] OS-level Implications of Using DRAM Caches in Memory Disaggregation
    Gao, Bin
    Tee, Hao-Wei
    Sanaee, Alireza
    Jun, Soh Boon
    Jevdjic, Djordje
    2022 IEEE INTERNATIONAL SYMPOSIUM ON PERFORMANCE ANALYSIS OF SYSTEMS AND SOFTWARE (ISPASS 2022), 2022, : 153 - 155
  • [18] Toward OS-Level and Device-Level Cooperative Scheduling for Multitasking GPUs
    Long, Xinjian
    Gong, Xiangyang
    Liu, Yaguang
    Que, Xirong
    Wang, Wendong
    IEEE ACCESS, 2020, 8 : 65711 - 65725
  • [19] Malware Clearance for Secure Commitment of OS-Level Virtual Machines
    Shan, Zhiyong
    Wang, Xin
    Chiueh, Tzi-cker
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2013, 10 (02) : 70 - 83
  • [20] The Kingsguard OS-level mitigation against cache side-channel attacks using runtime detection
    Maria Mushtaq
    Muhammad Muneeb Yousaf
    Muhammad Khurram Bhatti
    Vianney Lapotre
    Guy Gogniat
    Annals of Telecommunications, 2022, 77 : 731 - 747