Anomaly Detection of Program Behaviors Based on Data Mining and Variable-Length Sequence Matching
Xinguang Tian, Wenfa Li, Miyi Duan, Sun Chun-lai · Signal Processing · 2008
Network anomaly detection has been an active research topic in the field of Intrusion Detection for many years.This pa- per presents a new method for anomaly detection of program behaviors based on data mining and variable-length sequence pattern matc- hing.The method uses sequence patterns in data mining technique to model the normal behavior of a privileged program,extracts normal system call sequences according to their supports in the training data,and constructs multiple dictionaries of sequences of different lengths to represent the behavior profile of the program.At the detection stage,variable length sequences are matched to perform the comparison of the historic normal behaviors and current behaviors,and two different schemes can be used to determine whether the moni- tored program's behaviors are normal or anomalous while the particularity of program behaviors and audit data is taken into account.The application of the method in practical intrusion detection systems shows that it can achieve high detection performance.