Windows Registry Anomaly Detection Based on One-Class Support Vector Machines
Zhao Ze-mao · Computer Engineering and Science · 2009
As the core of the Microsoft Windows operating system,the registry controls the running of the whole Windows system. One of the most popular and most commonly attacked operating systems is Microsoft Windows. Malicious software often runs on the host machine to inflict attacks on the system. This paper presents a detection method for anomaly intrusion based on one-class support vector machines(SVM). It uses the normal Windows registry data set to train a detection model on a Windows host,and employs the SVM algorithm to detect abnormal registry accesses at run-time. The experimental results show that this approach can improve the generalization ability when less prior knowledge is given,and it also has the ability to detect unknown malicious programs and unknown intrusions. Meanwhile,the one-class support vector machines algorithm can reduce the detection time without decreasing the detection rate,and can greatly enhance the performance of the detection system.