Plan Recognition Based Method for Predicting Intrusion Intentions of System Call Sequences

冯力,管晓宏,郭三刚,高艳,刘培妮
DOI: https://doi.org/10.3321/j.issn:0254-4164.2004.08.010
2004-01-01
Chinese Journal of Computers
Abstract:Plan recognition is a prediction theory for identifying and determining the intentions or the attempts of the agents monitored through observation data. In this paper, a plan recognition based method is presented to predict the anomaly events and intensions of potential intruders to a computer system using the system call sequences as observation data. The method is established on a dynamic Bayesian network with parameter compensation and an algorithm is developed to update this network. The experimental results show that this method has a good accuracy in predicting the intrusion intensions from the system call sequences.
What problem does this paper attempt to address?