Probabilistic Program Modeling for High-Precision Anomaly Classification

被引:16
|
作者
Xu, Kui [1 ]
Yao, Danfeng [1 ]
Ryder, Barbara G. [1 ]
Tian, Ke [1 ]
机构
[1] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24060 USA
关键词
Anomaly detection; static program analysis; hidden Markov model; probability;
D O I
10.1109/CSF.2015.37
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The trend constantly being observed in the evolution of advanced modern exploits is their growing sophistication in stealthy attacks. Code-reuse attacks such as return-oriented programming allow intruders to execute mal-intended instruction sequences on a victim machine without injecting external code. We introduce a new anomaly-based detection technique that probabilistically models and learns a program's control flows for high-precision behavioral reasoning and monitoring. Our prototype in Linux is named STILO, which stands for STatically InitiaLized markOv. Experimental evaluation involves real-world code-reuse exploits and over 4,000 testcases from server and utility programs. STILO achieves up to 28-fold of improvement in detection accuracy over the state-of-the-art HMM-based anomaly detection. Our findings suggest that the probabilistic modeling of program dependences provides a significant source of behavior information for building high-precision models for real-time system monitoring.
引用
收藏
页码:497 / 511
页数:15
相关论文
共 50 条
  • [1] High-Precision Magnetic Field Reconstruction and Anomaly Classification
    Chang, Qing
    Liu, Ruiping
    Wang, Yaoli
    Wang, Lipo
    IEEE SENSORS JOURNAL, 2023, 23 (17) : 19163 - 19175
  • [2] A HIGH-PRECISION PARAMETER ESTIMATION PROGRAM
    HILT, DE
    ASTRONOMICAL JOURNAL, 1968, 73 (10P2): : S183 - &
  • [3] A COMPUTER PROGRAM FOR HIGH-PRECISION ORBIT DETERMINATION
    WARNER, MR
    ASTRONOMICAL JOURNAL, 1968, 73 (5P2): : S122 - &
  • [4] High-Precision Modeling and Optimization of Cogeneration Plants
    Chen, Stephanie
    Wassel, Dennis
    Bueskens, Christof
    ENERGY TECHNOLOGY, 2016, 4 (01) : 177 - 186
  • [5] High-precision modeling of deformation of laminated structures
    A. G. Gurtovyi
    Mechanics of Composite Materials, 1999, 35 : 7 - 18
  • [6] High-precision modeling of deformation of laminated structures
    Gurtovyi, AG
    MECHANICS OF COMPOSITE MATERIALS, 1999, 35 (01) : 7 - 18
  • [7] Friction modeling of a high-precision positioning system
    Thiery, Sebastien
    Kunze, Marc
    Karimi, Alireza
    Curnier, Alain
    Longchamp, Roland
    2006 AMERICAN CONTROL CONFERENCE, VOLS 1-12, 2006, 1-12 : 1863 - +
  • [8] INFORMATION EXTRACTION AS A BASIS FOR HIGH-PRECISION TEXT CLASSIFICATION
    RILOFF, E
    LEHNERT, W
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 1994, 12 (03) : 296 - 333
  • [9] High-precision accounting for high-precision network services
    Clemm, Alexander
    Strassner, John
    2021 IEEE 22ND INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2021,
  • [10] A High-precision Approach of Traffic Anomaly Based on Fractal and Binary Symbolic
    Sun Meiyu
    Lv Xinjun
    2013 NINTH INTERNATIONAL CONFERENCE ON SEMANTICS, KNOWLEDGE AND GRIDS (SKG), 2013, : 182 - 185