Anomaly detection based on grammar

Jin-zhong HUANG,Miao-liang ZHU,Ye GUO
DOI: https://doi.org/10.3785/j.issn.1008-973X.2006.02.014
2006-01-01
Abstract:Current anomaly detection technique cannot provide any valuable information except simple alarm. To resolve this problem, a new anomaly detection method was proposed. The system call traces are represented as a kind of hierarchy model composed of system call, operation, transition and activity, while the normal program behavior is described using a context-free grammar with semantic labels attached. Some key system calls and their parameters or return values are used to segment and learn normal traces. Experimental results show that this method can effectively detect attacks exploiting vulnerabilities, and can also analyze anomaly scenes and provide much information on anomalous events including intruders' IP addresses.
What problem does this paper attempt to address?