Decision Tree Algorithm-based Host Anomaly Detection Using Windows Native API Sequences

LI Nai-jie,PENG Qin-ke
DOI: https://doi.org/10.3969/j.issn.1001-3695.2007.01.082
2007-01-01
Abstract:Anomaly detection algorithm for Windows platform is studied.A host process pattern extraction algorithm using Windows Native API sequences and based on decision tree is presented,and a wildcard is introduced in patterns,so the size of pattern set is reduced considerably.More over,transition probabilities between patterns are computed to build a global Markov Chain Model of pattern sequences,and related anomaly detection algorithm is presented.Experiments demonstrate that the algorithms can extract a pattern set of small size and high generalization ability,and can detect anomalies effectively.
What problem does this paper attempt to address?