A Detection Method Based on K-Cores Algorithm for Abnormal Processes in the Server
Jing Du, Fujiang Ao, Yaxin Zhao, Yinglong Liu · 2019
The server is an important node that provides data processing and service in the network, and its safe operation is critical. In order to prevent malicious attacks, it is necessary to discover malicious processes in the server as early as possible. This paper proposes an innovative method of the process whitelist based on the K-Cores graph algorithm, and takes this as a baseline to detect abnormal processes in the server. This method transforms the relationship between the server and the process into a topology map, and converts the problem of legal process analysis into the problem of the node's importance analysis in the network graph, and then uses the K-Cores algorithm to group the nodes according to the importance. In the network diagram the process corresponding to the node full of importance is written to the whitelist as a legal process. This paper uses an unsupervised method to detect abnormal processes running on the server, remove security risks such as backdoor processes, which effectively improves the security performance of the server.