Using information theory to measure call site information of system call in anomaly detection
Feng Xie, Lixia Xie · 2013
It is an important and effective approach for the detection of network attacks by means of monitoring and analyzing the running behavior of the program. Traditionally, a program can be characterized by system call issued by it. The call site information of system call, however, is often ignored by many system-call-based detection models. This paper evaluates the influence of the specific information on program behavior by means of information-theoretic measure. Experimental results show that the information could lower conditional entropy as well as relative conditional entropy, which contribute to more precise model and more effective detection for intrusions.