A Useful Intrusion Detection System Prototype to Monitor Multi-processes Based on System Calls

  • Authors:
  • Hongpei Li;Lianli Chang;Xinmei Wang

  • Affiliations:
  • -;-;-

  • Venue:
  • ICICS '01 Proceedings of the Third International Conference on Information and Communications Security
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Based on studying of process behaviors classification, a practical intrusion detection system prototype is discussed. As one of the key elements, the system behaviors classifier (Naive Bayesian Classifier) can identify malicious system behaviors effectively by classifying the sequences of system calls as normal or abnormal. However, an extended intrusion detection mechanism by monitoring multiple processes to detect intrusions that can modify the behaviors of system programs (such as: Trojan Horses, Buffer overflow attacks, and viruses.) is proposed.