Detecting the deviations of privileged process execution

  • Authors:
  • Purui Su;Dequan Li;Haipeng Qu;Dengguo Feng

  • Affiliations:
  • State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing, Beijing, P.R. China;State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing, Beijing, P.R. China;State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing, Beijing, P.R. China;State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing, Beijing, P.R. China

  • Venue:
  • ICN'05 Proceedings of the 4th international conference on Networking - Volume Part II
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Most intruders access system unauthorizedly by exploiting vulnerabilities of privileged processes. Respectively monitoring privileged processes via system call sequences is one of effective methods to detect intrusions. Based on the analysis of popular attacks, we bring forward a new intrusion detection model monitoring the system call sequences, which use locally fuzzy matching to improve the detection accuracy. And the model adopts a novel profile generation method, which could easily generate better profile. The experimental results show that both the accuracy and the efficiency have been improved.