Selecting and Improving System Call Models for Anomaly Detection [chapter]

Alessandro Frossi, Federico Maggi, Gian Luigi Rizzo, Stefano Zanero
2009 Lecture Notes in Computer Science  
We propose a syscall-based anomaly detection system that incorporates both deterministic and stochastic models. We analyze in detail two alternative approaches for anomaly detection over system call sequences and arguments, and propose a number of modifications that significantly improve their performance. We begin by comparing them and analyzing their respective performance in terms of detection accuracy. Then, we outline their major shortcomings, and propose various changes in the models that
more » ... can address them: we show how targeted modifications of their anomaly models, as opposed to the redesign of the global system, can noticeably improve the overall detection accuracy. Finally, the impact of these modifications are discussed by comparing the performance of the two original implementations with two modified versions complemented with our models.
doi:10.1007/978-3-642-02918-9_13 fatcat:ig2yhvyi7rbfhns6db4aonmoza