An new intrusion detection method based on linear prediction

  • Authors:
  • Qingbo Yin;Rubo Zhang;Xueyao Li

  • Affiliations:
  • University, Harbin, PR China;University, Harbin, PR China;University, Harbin, PR China

  • Venue:
  • InfoSecu '04 Proceedings of the 3rd international conference on Information security
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Intrusion detection has emerged as an important approach to network security. A new method for anomaly intrusion detection is proposed based on linear prediction and Markov chain model. Linear prediction is employed to extract features from system calls sequences of the privileged processes, and the Markov chain model is founded based on those features. The observed behavior of the system is analyzed to infer the probability that the Markov chain model of the norm profile supports the observed behavior. A low probability of support indicates an anomalous behavior that may result from intrusive activities. Markov information source entropy (MISE) and condition entropy (CE) are used to select parameters. The merits of the model are simple and exact to predict. The experiments show this method is effective and efficient, and can be used in practice to monitor the computer system in real time.