A Markov Model of System Calls Sequence and Its Application in Anomaly Detection

谭小彬,王卫平,奚宏生,殷保群
DOI: https://doi.org/10.3969/j.issn.1000-3428.2002.12.073
2002-01-01
Abstract:The paper builds a Markov model of system calls sequence on computer system for intrusion detection, and introduces an anomaly detection method for computer systems. It analyses the current system calls sequences by using the knowledge on statistics, then defines a mismatch factor based on transition probabilities to compute the mismatch rate, and judges whether the process is in normal state or not by analyzing the mismatch rate. It also gives an updated algorithm of transition probabilities based on forgetting factor.
What problem does this paper attempt to address?