Probabilistic Anomaly Detection Based On System Calls Analysis

Przemysław Maciołek, Paweł Król, Jarosław Koźlak · DOAJ (DOAJ: Directory of Open Access Journals) · 2007

We present an application of probabilistic approach to the anomaly detection (PAD). Byanalyzing selected system calls (and their arguments), the chosen applications are monitoredin the Linux environment. This allows us to estimate “(ab)normality” of their behavior (bycomparison to previously collected profiles). We’ve attached results of threat detection ina typical computer environment.

Read the paper · More papers on PaperTik