Probabilistic Program Modeling for High-Precision Anomaly Classification

被引:16
|
作者
Xu, Kui [1 ]
Yao, Danfeng [1 ]
Ryder, Barbara G. [1 ]
Tian, Ke [1 ]
机构
[1] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24060 USA
关键词
Anomaly detection; static program analysis; hidden Markov model; probability;
D O I
10.1109/CSF.2015.37
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The trend constantly being observed in the evolution of advanced modern exploits is their growing sophistication in stealthy attacks. Code-reuse attacks such as return-oriented programming allow intruders to execute mal-intended instruction sequences on a victim machine without injecting external code. We introduce a new anomaly-based detection technique that probabilistically models and learns a program's control flows for high-precision behavioral reasoning and monitoring. Our prototype in Linux is named STILO, which stands for STatically InitiaLized markOv. Experimental evaluation involves real-world code-reuse exploits and over 4,000 testcases from server and utility programs. STILO achieves up to 28-fold of improvement in detection accuracy over the state-of-the-art HMM-based anomaly detection. Our findings suggest that the probabilistic modeling of program dependences provides a significant source of behavior information for building high-precision models for real-time system monitoring.
引用
收藏
页码:497 / 511
页数:15
相关论文
共 50 条
  • [21] Bayesian inference for neural network based high-precision modeling
    Morales, Jorge
    Yu, Wen
    2022 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2022, : 442 - 447
  • [22] Modeling the rail surface unevenness of a high-precision radio telescope
    Na Li
    Peng Li
    Jiang Wu
    Bao-Yan Duan
    ResearchinAstronomyandAstrophysics, 2017, 17 (03) : 15 - 24
  • [23] Nonlinear friction modeling and compensation of high-precision experimental platforms
    Xiang H.-B.
    Qiu Z.-R.
    Li X.-F.
    Tan W.-B.
    Zhu J.
    Chen C.
    Zhang C.-Y.
    Guangxue Jingmi Gongcheng/Optics and Precision Engineering, 2010, 18 (05): : 1119 - 1127
  • [24] A high-precision electromagnetic technique for modeling and simulation in inhomogeneous media
    Yang, Xin
    Wei, Bing
    WAVES IN RANDOM AND COMPLEX MEDIA, 2020, 30 (01) : 107 - 117
  • [25] High-precision modeling and collision simulation of small rotor UAV
    Zhang, Yongjie
    Huang, Yingjie
    Liang, Ke
    Cao, Kang
    Wang, Yafeng
    Liu, Xiaochuan
    Guo, Yazhou
    Wang, Jizhen
    AEROSPACE SCIENCE AND TECHNOLOGY, 2021, 118
  • [26] HIGH-PRECISION BAYESIAN MODELING OF SAMPLES SUSCEPTIBLE TO INBUILT AGE
    Dee, M. W.
    Ramsey, C. Bronk
    RADIOCARBON, 2014, 56 (01) : 83 - 94
  • [27] Large-Scale High-Precision Topic Modeling on Twitter
    Yang, Shuang
    Kolcz, Alek
    Schlaikjer, Andy
    Gupta, Pankaj
    PROCEEDINGS OF THE 20TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING (KDD'14), 2014, : 1907 - 1916
  • [28] Protein Structure Determination by High-Precision FRET and Molecular Modeling
    Dimura, Mykola
    Peulen, Thomas
    Gohlke, Holger
    Seidel, Claus A. M.
    BIOPHYSICAL JOURNAL, 2017, 112 (03) : 48A - 48A
  • [29] A high-precision magnetometer
    Golubev, A. A.
    Ignat'ev, V. K.
    Nikitin, A. V.
    INSTRUMENTS AND EXPERIMENTAL TECHNIQUES, 2008, 51 (05) : 753 - 758
  • [30] HIGH-PRECISION DISPLAYS
    SWENINGS.ES
    INDUSTRIAL PHOTOGRAPHY, 1969, 18 (11): : 30 - &