An OS-level Framework for Anomaly Detection in Complex Software Systems

被引:17
|
作者
Bovenzi, Antonio [1 ]
Brancati, Francesco [2 ]
Russo, Stefano [1 ]
Bondavalli, Andrea [3 ]
机构
[1] Univ Naples Federico II, Dipartimento Ingn Elettr & Tecnol Informaz, Naples, Italy
[2] Resiltech SRL, Pontedera, PI, Italy
[3] Univ Florence, Dipartimento Sistemi & Informat, I-50121 Florence, Italy
关键词
Anomaly-detection; system monitoring; operating system; mission-critical systems;
D O I
10.1109/TDSC.2014.2334305
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Revealing anomalies at the operating system (OS) level to support online diagnosis activities of complex software systems is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) are inadequate or cannot be applied. In this paper we propose a configurable detection framework to reveal anomalies in the OS behavior, related to system misbehaviors. The detector is based on online statistical analyses techniques, and it is designed for systems that operate under variable and non-stationary conditions. The framework is evaluated to detect the activation of software faults in a complex distributed system for Air Traffic Management (ATM). Results of experiments with two different OSs, namely Linux Red Hat EL5 and Windows Server 2008, show that the detector is effective for mission-critical systems. The framework can be configured to select the monitored indicators so as to tune the level of intrusivity. A sensitivity analysis of the detector parameters is carried out to show their impact on the performance and to give to practitioners guidelines for its field tuning.
引用
收藏
页码:366 / 372
页数:7
相关论文
共 50 条
  • [21] MADneSs: A Multi-Layer Anomaly Detection Framework for Complex Dynamic Systems
    Zoppi, Tommaso
    Ceccarelli, Andrea
    Bondavalli, Andrea
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (02) : 796 - 809
  • [22] A pattern-based framework for software anomaly detection
    Kothari, SC
    Bishop, L
    Sauceda, J
    Daugherty, G
    SOFTWARE QUALITY JOURNAL, 2004, 12 (02) : 99 - 120
  • [23] A Pattern-Based Framework for Software Anomaly Detection
    S.C. Kothari
    Luke Bishop
    Jeremias Sauceda
    Gary Daugherty
    Software Quality Journal, 2004, 12 : 99 - 120
  • [24] The Kingsguard OS-level mitigation against cache side-channel attacks using runtime detection
    Mushtaq, Maria
    Yousaf, Muhammad Muneeb
    Bhatti, Muhammad Khurram
    Lapotre, Vianney
    Gogniat, Guy
    ANNALS OF TELECOMMUNICATIONS, 2022, 77 (11-12) : 731 - 747
  • [25] XConveryer: Guarantee Hadoop Throughput via Lightweight OS-level Virtualization
    Qin, An
    Tu, Dandan
    Shu, Chengchun
    Gao, Chang
    2009 EIGHTH INTERNATIONAL CONFERENCE ON GRID AND COOPERATIVE COMPUTING, PROCEEDINGS, 2009, : 299 - +
  • [26] Mitigating Interference between Scientific Applications in OS-Level Virtualized Environments
    Adufu, Theodora
    Kim, Yoonhee
    SCIENTIFIC PROGRAMMING, 2018, 2018
  • [27] Anomaly Detection in Complex Trading Systems
    Ranaweera, Lochana
    Vithanage, Ruchindra
    Dissanayake, Amitha
    Prabodha, Chamil
    Ranathunga, Surangika
    2017 3RD INTERNATIONAL MORATUWA ENGINEERING RESEARCH CONFERENCE (MERCON), 2017, : 437 - 442
  • [28] Model-driven Configuration of OS-level Mandatory Access Control
    Agreiter, Berthold
    ICSE'08 PROCEEDINGS OF THE THIRTIETH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 2008, : 995 - 998
  • [29] Combating the OS-Level Malware in Mobile Devices by Leveraging Isolation and Steganography
    Chen, Niusen
    Xie, Wen
    Chen, Bo
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2021, 2021, 12809 : 397 - 413
  • [30] Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization
    Shan, Zhiyong
    Wang, Xin
    Chiueh, Tzi-cker
    IEEE TRANSACTIONS ON COMPUTERS, 2014, 63 (05) : 1220 - 1233