HMMs (Hidden Markov models) based on anomaly intrusion detection method

Bo Gao,Huiye Ma,Yuhang Yang
DOI: https://doi.org/10.1109/ICMLC.2002.1176779
2002-01-01
Abstract:In this paper we discuss our research in developing anomaly detecting method for intrusion detection. The key idea is to use HMMs (Hidden Markov models) to learn the (normal and abnormal) patterns of Unix processes. These patterns can be used to detect anomalies and known intrusion. Using experiments on the mail-sending system call data, we demonstrate that we can construct concise and accurate classifiers to detect intrusion action.
What problem does this paper attempt to address?