Finding the vocabulary of program behavior data for anomaly detection

C. C. Michael · 2004

Application-based anomaly detectors construct a base-line model of normal application behavior, and deviations from that behavior are interpreted as signs of a possible intrusion. But current anomaly detectors monitor application behavior at a high level of detail, and many irrelevant variations in that behavior can cause false alarms. This paper discusses the preprocessing of audit data ultimately used by application-based anomaly detection systems. The goal is to create a more abstract picture of program behavior filtering out many irrelevant details. Our specific approach automatically identifies repeating sub-sequences of behavior events and sequences of events that always occur together. The main benefit of this preprocessing technique can be used with a wide variety of program-based anomaly detectors, but we present empirical results showing how it improves the performance of the well-known stide anomaly detection system.

Read the paper · More papers on PaperTik