Detecting anomalous process using gapped string kernels

Chuanhuan Yin,Shengfeng Tian,Shaomin Mu
2006-01-01
Journal of Computational Information Systems
Abstract:In order to detect anomalous process, a one-class support vector machine (SVM) classifier is constructed based on monitoring the system calls of normal process, and the classifier is used to detect intrusions. To use the sequence information in system call sequences, two new string kernels are presented. These belong to the family of gapped string kernels. They are length-weighted kernels and length-weighted once kernels. The kernels which concern the matches of subsequences (contiguous or non-contiguous) within two strings are called gapped string kernels. These include subsequence kernels and gap-weighted kernels. All gapped string kernels and RBF kernel are tested with an SVM classifier on the UNM datasets. The experimental results reveal that the length-weighted once kernels outperform the others gapped string kernels as well as RBF kernel.
What problem does this paper attempt to address?