articleJan 20, 2003Closed access

Detecting intrusions using system calls: alternative data models

University of New Mexico

Indexed incrossref

Abstract

Intrusion detection systems rely on a wide variety of observable data to distinguish between legitimate and illegitimate activities. We study one such observable-sequences of system calls into the kernel of an operating system. Using system-call data sets generated by several different programs, we compare the ability of different data modeling methods to represent normal behavior accurately and to recognize intrusions. We compare the following methods: simple enumeration of observed sequences; comparison of relative frequencies of different sequences; a rule induction technique; and hidden Markov models (HMMs). We discuss the factors affecting the performance of each method and conclude that for this…

Citation impact

1,104
total citations
FWCI
72.02
Percentile
100%
References
18
Citations per year

Authors

3

Topics & keywords

Keywords
  • System call
  • Intrusion detection system
  • Observable
  • Hidden Markov model
  • Computer science
  • Kernel (algebra)
  • Data mining
  • Simple (philosophy)
UN Sustainable Development Goals
  • Peace, Justice and strong institutions
No related works found for this paper.