Markov Chain Intrusion Detection Model Based on System Call Macro

XU Ming,DING Hong,CHEN Chun
DOI: https://doi.org/10.3785/j.issn.1008-973x.2005.02.008
2005-01-01
Abstract:In order to exactly and rapidly detect anomaly, a detection model that can exactly depict the profiles of normal process actions was proposed. The consistently repeated system call sequences in normal process traces were regarded as macros, then a Markov chains anomaly detection model based on system call macros was constructed. Conclusions were drawn by comparing the performance metrics of Macro MCM (Markov chains model) with the first-order MCM and second-order MCM based on system call. The comparison shows that in detection performance (hit rates and false alarm rates), Macro MCM is better than the other two models; in needed memory capability, Macro MCM is more than the first-order MCM, but less than the second-order MCM; in computing speed, the training speed of Macro MCM is the slowest among three models, but its detection speed is the highest.
What problem does this paper attempt to address?