A Method for Host Abnormal Detection Based on Resource Availability

TAO Jing,MA Xiao-bo,ZHAO Juan,ZHENG Qing-hua
DOI: https://doi.org/10.3969/j.issn.1001-0548.2007.06.026
2007-01-01
Abstract:Abnormal behaviors of hosts are complicated and diversified caused by many factors. However, they are often incarnated by the usage of resouces such as CPU, memory, bandwidth, etc. In this paper, a novel method for anomaly detection based on Host Resource Availability (HRA) is presented. Firstly, an index system is established to describe the usage of host resource. Secondly, a normal profile of HRA is extracted by experiment. Finally, an algorithm called Double-Threshold Anomaly Detection Algorithm (DTADA ) is put forward according to the particularity of HRA. Application testing shows that our method has a satisfied result.
What problem does this paper attempt to address?