Classification of anomalous traces of privileged and parallel programs by neural networks
Zhen Liu, S.M. Bridges, Rayford B. Vaughn · 2004
The focus of intrusion detection has recently shifted from user-based and connection-based to process-based intrusion detection. Substantial research has been done in the analysis of system call logs using different methods including neural networks. Detection is based on the classification of short sequences as anomalous or normal. The classification of interest, however, is the status of the program trace, not just the short sequences. In this paper we report the results of a comparative study of three different methods for on-line classification of program traces based detection of anomalies in sequences of system calls by neural networks. These results demonstrate that methods that use information about the locality of anomalies are more effective than those that only look at the number of anomalies.