An OS-level Framework for Anomaly Detection in Complex Software Systems

被引:17
|
作者
Bovenzi, Antonio [1 ]
Brancati, Francesco [2 ]
Russo, Stefano [1 ]
Bondavalli, Andrea [3 ]
机构
[1] Univ Naples Federico II, Dipartimento Ingn Elettr & Tecnol Informaz, Naples, Italy
[2] Resiltech SRL, Pontedera, PI, Italy
[3] Univ Florence, Dipartimento Sistemi & Informat, I-50121 Florence, Italy
关键词
Anomaly-detection; system monitoring; operating system; mission-critical systems;
D O I
10.1109/TDSC.2014.2334305
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Revealing anomalies at the operating system (OS) level to support online diagnosis activities of complex software systems is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) are inadequate or cannot be applied. In this paper we propose a configurable detection framework to reveal anomalies in the OS behavior, related to system misbehaviors. The detector is based on online statistical analyses techniques, and it is designed for systems that operate under variable and non-stationary conditions. The framework is evaluated to detect the activation of software faults in a complex distributed system for Air Traffic Management (ATM). Results of experiments with two different OSs, namely Linux Red Hat EL5 and Windows Server 2008, show that the detector is effective for mission-critical systems. The framework can be configured to select the monitored indicators so as to tune the level of intrusivity. A sensitivity analysis of the detector parameters is carried out to show their impact on the performance and to give to practitioners guidelines for its field tuning.
引用
收藏
页码:366 / 372
页数:7
相关论文
共 50 条
  • [31] UTrack: Enterprise User Tracking Based on OS-Level Audit Logs
    Li, Yue
    Wu, Zhenyu
    Wang, Haining
    Sun, Kun
    Li, Zhichun
    Jee, Kangkook
    Rhee, Junghwan
    Chen, Haifeng
    PROCEEDINGS OF THE ELEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '21), 2021, : 161 - 172
  • [32] Palisade: A framework for anomaly detection in embedded systems
    Kauffman, Sean
    Dunne, Murray
    Gracioli, Giovani
    Khan, Waleed
    Benann, Nirmal
    Fischmeister, Sebastian
    JOURNAL OF SYSTEMS ARCHITECTURE, 2021, 113
  • [33] A Coordinated Approach for Practical OS-Level Cache Management in Multi-Core Real-Time Systems
    Kim, Hyoseung
    Kandhalu, Arvind
    Rajkumar, Ragunathan
    PROCEEDINGS OF THE 2013 25TH EUROMICRO CONFERENCE ON REAL-TIME SYSTEMS (ECRTS 2013), 2013, : 80 - 89
  • [34] An OS-level Data Distribution Method in DRAM-PCM Hybrid Memory
    Zhang, Hongbin
    Fan, Jie
    Shu, Jiwu
    ADVANCED COMPUTER ARCHITECTURE, ACA 2016, 2016, 626 : 1 - 14
  • [35] Large-Scale IP Network Testbed Based on OS-level virtualization
    Li Dawei
    Wang Rui
    2013 INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA (CLOUDCOM-ASIA), 2013, : 409 - 413
  • [36] A Survey on Recent OS-Level Energy Management Techniques for Mobile Processing Units
    Kim, Young Geun
    Kong, Joonho
    Chung, Sung Woo
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2018, 29 (10) : 2388 - 2401
  • [37] Challenging Anomaly Detection in Complex Dynamic Systems
    Zoppi, Tommaso
    Ceccarelli, Andrea
    Bondavalli, Andrea
    PROCEEDINGS OF 2016 IEEE 35TH SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS), 2016, : 213 - 214
  • [38] Adonis: Practical and Efficient Control Flow Recovery through OS-level Traces
    Liu, Xuanzhe
    Yang, Chengxu
    Li, Ding
    Zhou, Yuhan
    Li, Shaofei
    Chen, Jiali
    Chen, Zhenpeng
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2024, 33 (01)
  • [39] Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level Virtualization
    Yang, Nanzi
    Shen, Wenbo
    Li, Jinku
    Yang, Yutian
    Lu, Kangjie
    Xiao, Jietao
    Zhou, Tianyu
    Qin, Chenggang
    Yu, Wang
    Ma, Jianfeng
    Ren, Kui
    CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 764 - 778
  • [40] Performance evaluation of memory management configurations in linux for an OS-level design space exploration
    Park, Sangsoo
    Shin, Heonshik
    EMBEDDED COMPUTER SYSTEMS: ARCHITECTURES, MODELING, AND SIMULATION - PROCEEDINGS, 2007, 4599 : 24 - +