A New Study of the System Call Sequence Analysis Method

Ling DONG,Hongli ZHANG,Lin YE
DOI: https://doi.org/10.3969/j.issn.2095-2163.2014.04.004
2014-01-01
Abstract:System calls are the interface between operating system and user programs.Execution of each program must use some system calls.In recent years,network security incidents occur frequently,intrusion detection method based on the system call sequence analysis has become one of the hot network security technology researches.This paper presents a multi-layer model of program behaviours based on both hidden Markov models and enumerating methods,which differs from the conventional single layer approach.On experimental data provided by the University of New Mexico,experimental results have shown that the model is better in detecting anomalous behaviour of programs in terms of accuracy and response time, which indicates that this method is suitable for online host -based intrusion detection systems.
What problem does this paper attempt to address?