Intrusion Detection System Based on Integrated System Calls Graph and Neural Networks

被引:10
|
作者
Mora-Gimeno, F. J. [1 ]
Mora-Mora, H. [1 ]
Volckaert, B. [2 ]
Atrey, A. [2 ]
机构
[1] Univ Alicante, Dept Comp Technol, San Vicente Del Raspeig 03690, Spain
[2] Univ Ghent, Dept Informat Technol, B-9000 Ghent, Belgium
来源
IEEE ACCESS | 2021年 / 9卷 / 09期
关键词
Intrusion detection; Proposals; Hidden Markov models; Neural networks; Analytical models; Data structures; Text categorization; Anomaly detection; intrusion detection system; neural networks; system calls graph; DEEP LEARNING APPROACH; MODEL;
D O I
10.1109/ACCESS.2021.3049249
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Computer security is one of the main challenges of today's technological infrastructures, whereas intrusion detection systems are one of the most widely used technologies to secure computer systems. The intrusion detection systems use a variety of information sources, one of the most important sources are the applications' system calls. The intrusion detection systems use many different detection techniques, e.g. system calls sequences, text classification techniques and system calls graphs. However, existing techniques obtain poor results in the detection of complex attack patterns, so it is necessary to improve the detection results. This paper presents an intrusion detection system model that integrates multiple detection techniques into a single system with the goal of modeling the global behavior of the applications. In addition, the paper proposes a new modified system calls graph to integrate and represent the information of the different techniques in a single data structure. The system uses a deep neural network to combine the results of the different detection techniques used in the global model. The result of the study shows the improvement obtained in the detection results with respect to the use of individual techniques, the proposed model achieves higher detection rates and lower false positives. The proposal has been validated onto three datasets with different levels of complexity.
引用
收藏
页码:9822 / 9833
页数:12
相关论文
共 50 条
  • [1] An Integrated Intrusion Detection System by Using Multiple Neural Networks
    Liu, Guisong
    Wang, Xiaobin
    [J]. 2008 IEEE CONFERENCE ON CYBERNETICS AND INTELLIGENT SYSTEMS, VOLS 1 AND 2, 2008, : 724 - 729
  • [2] An Intrusion detection system for network storage based on system calls
    Geng, Li-zhong
    Jia, Hui-bo
    [J]. FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 544 - +
  • [3] Applying fuzzy neural network to intrusion detection based on sequences of system calls
    Zhang, GL
    Sun, JH
    [J]. ADVANCED DATA MINING AND APPLICATIONS, PROCEEDINGS, 2005, 3584 : 483 - 490
  • [4] Graph Embedding for Graph Neural Network in Intrusion Detection System
    Dinh-Hau Tran
    Park, Minho
    [J]. 38TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN 2024, 2024, : 395 - 397
  • [5] Graph-Based Intrusion Detection System for Controller Area Networks
    Islam, Riadul
    Refat, Rafi Ud Daula
    Yerram, Sai Manikanta
    Malik, Hafiz
    [J]. IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (03) : 1727 - 1736
  • [6] Detection engine based on host system calls for distributed intrusion detection system
    Peng, XG
    Mi, WT
    Liu, YS
    Wu, YS
    [J]. ISTM/2003: 5TH INTERNATIONAL SYMPOSIUM ON TEST AND MEASUREMENT, VOLS 1-6, CONFERENCE PROCEEDINGS, 2003, : 3441 - 3444
  • [7] LLE on system calls for host based intrusion detection
    Dash, Subrat Kumar
    Rawat, Sanjay
    Pujari, Arun K.
    [J]. 2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 609 - 612
  • [8] An integrated model of intrusion detection based on neural network and expert system
    Pan, ZS
    Lian, H
    Hu, GY
    Ni, GQ
    [J]. ICTAI 2005: 17TH IEEE INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2005, : 671 - 672
  • [9] Intrusion Detection System Modeling Based on Neural Networks and Fuzzy Logic
    Midzic, A.
    Avdagic, Z.
    Omanovic, S.
    [J]. INES 2016 20th Jubilee IEEE International Conference on Intelligent Engineering Systems, 2016, : 189 - 194
  • [10] Anomal-E: A self-supervised network intrusion detection system based on graph neural networks
    Caville, Evan
    Lo, Wai Weng
    Layeghy, Siamak
    Portmann, Marius
    [J]. KNOWLEDGE-BASED SYSTEMS, 2022, 258