A Real-Time Intrusion Detection System Based on Learning Program Behavior

  • Authors:
  • Anup K. Ghosh;Christoph Michael;Michael Schatz

  • Affiliations:
  • -;-;-

  • Venue:
  • RAID '00 Proceedings of the Third International Workshop on Recent Advances in Intrusion Detection
  • Year:
  • 2000

Quantified Score

Hi-index 0.00

Visualization

Abstract

In practice, most computer intrusions begin by misusing programs in clever ways to obtain unauthorized higher levels of privilege. One effective way to detect intrusive activity before system damage is perpetrated is to detect misuse of privileged programs in real-time. In this paper, we describe three machine learning algorithms that learn the normal behavior of programs running on the Solaris platform in order to detect unusual uses or misuses of these programs. The performance of the three algorithms has been evaluated by an independent laboratory in an off-line controlled evaluation against a set of computer intrusions and normal usage to determine rates of correct detection and false alarms. A real-time system has since been developed that will enable deployment of a program-based intrusion detection system in a real installation.