Low-cost Intrusion Detection Method Based on Statistical Language Models

耿立中,贾惠波
DOI: https://doi.org/10.3969/j.issn.1000-3428.2010.05.004
2010-01-01
Abstract:The existing intrusion detection methods based on sequences of system calls have a large overhead to construct normal profile.An efficient algorithm using statistical language models is proposed based on STIDE in order to reduce the computing cost.The system calls which can represent the characteristics of normal behaviors are extracted by an N-gram method.The improved algorithm extracts the most relevant sequences of system calls.Experimental results demonstrate that the computing cost of the improved algorithm has a reduction of 70% than the standard one and no degradation of detecting rate and false positive rate.
What problem does this paper attempt to address?