Probabilistic Program Modeling for High-Precision Anomaly Classification

被引:16
|
作者
Xu, Kui [1 ]
Yao, Danfeng [1 ]
Ryder, Barbara G. [1 ]
Tian, Ke [1 ]
机构
[1] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24060 USA
关键词
Anomaly detection; static program analysis; hidden Markov model; probability;
D O I
10.1109/CSF.2015.37
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The trend constantly being observed in the evolution of advanced modern exploits is their growing sophistication in stealthy attacks. Code-reuse attacks such as return-oriented programming allow intruders to execute mal-intended instruction sequences on a victim machine without injecting external code. We introduce a new anomaly-based detection technique that probabilistically models and learns a program's control flows for high-precision behavioral reasoning and monitoring. Our prototype in Linux is named STILO, which stands for STatically InitiaLized markOv. Experimental evaluation involves real-world code-reuse exploits and over 4,000 testcases from server and utility programs. STILO achieves up to 28-fold of improvement in detection accuracy over the state-of-the-art HMM-based anomaly detection. Our findings suggest that the probabilistic modeling of program dependences provides a significant source of behavior information for building high-precision models for real-time system monitoring.
引用
收藏
页码:497 / 511
页数:15
相关论文
共 50 条
  • [41] HIGH-PRECISION REFLECTOMETER
    CHERNOV, EI
    GOLOVKOV, OL
    SOVIET JOURNAL OF OPTICAL TECHNOLOGY, 1990, 57 (03): : 158 - 159
  • [42] High-precision EDM
    不详
    MANUFACTURING ENGINEERING, 2006, 137 (06): : 45 - 45
  • [43] Clustering and Hierarchical Classification for High-Precision RFID Indoor Location Systems
    Gomes, Eduardo Luis
    Fonseca, Mauro
    Lazzaretti, Andre Eugenio
    Munaretto, Anelise
    Guerber, Carlos
    IEEE SENSORS JOURNAL, 2022, 22 (06) : 5141 - 5149
  • [44] An MRS-YOLO Model for High-Precision Waste Detection and Classification
    Ren, Yuanming
    Li, Yizhe
    Gao, Xinya
    SENSORS, 2024, 24 (13)
  • [45] A high-precision image classification network model based on a voting mechanism
    Zhao, Jianghong
    Wang, Xin
    Dou, Xintong
    Zhao, Yingxue
    Fu, Zexin
    Guo, Ming
    Zhang, Ruiju
    INTERNATIONAL JOURNAL OF DIGITAL EARTH, 2022, 15 (01) : 2168 - 2183
  • [46] Towards High-Precision Stroke Classification Using Natural Language Processing
    Majersik, Jennifer J.
    Mowery, Danielle
    Zhang, Mingyuan
    Hill, Brent
    Cannon-Albright, Lisa A.
    Chapman, Wendy
    STROKE, 2018, 49
  • [47] High-precision modeling of dynamic etching in high-power magnetron sputtering
    Cui, Suihan
    Chen, Qiuhao
    Guo, Yuxiang
    Chen, Lei
    Jin, Zheng
    Li, Xiteng
    Yang, Chao
    Wu, Zhongcan
    Su, Xiongyu
    Ma, Zhengyong
    Fu, Ricky K. Y.
    Tian, Xiubo
    Chu, Paul K.
    Wu, Zhongzhen
    JOURNAL OF PHYSICS D-APPLIED PHYSICS, 2022, 55 (32)
  • [48] Seismic Facies-Guided High-Precision Geological Anomaly Identification Method and Application
    Duan, Jing
    Zhang, Gulan
    You, Jiachun
    Hu, Guanghui
    Luo, Yiliang
    Ran, Shiyun
    Zhong, Qihong
    Cao, Caijun
    Tang, Wenjie
    Liang, Chenxi
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62
  • [49] Automatic, high-speed, high-precision acquisition scheme with QPD for the Taiji program
    Gao, Ruihong
    Liu, Heshan
    Zhao, Ya
    Luo, Ziren
    Jin, Gang
    OPTICS EXPRESS, 2021, 29 (02): : 821 - 836
  • [50] Online High-Precision Probabilistic Localization of Robotic Fish Using Visual and Inertial Cues
    Wang, Wei
    Xie, Guangming
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2015, 62 (02) : 1113 - 1124