Abstract
This paper addresses the problem of creating patterns that can be used to model the normal behavior of a given process. The models can be used for intrusion-detection purposes. First, we present a novel method to generate input data sets that enable us to observe the normal behavior of a process in a secure environment. Second, we propose various techniques to derive either fixed-length or variable-length patterns from the input data sets. We show the advantages and drawbacks of each technique, based on the results of the experiments we have run on our testbed.
| Original language | English |
|---|---|
| Pages (from-to) | 159-181 |
| Number of pages | 23 |
| Journal | Journal of Computer Security |
| Volume | 8 |
| Issue number | 2 |
| DOIs | |
| Publication status | Published - 1 Jan 2000 |
| Externally published | Yes |
Fingerprint
Dive into the research topics of 'Fixed- vs. variable-length patterns for detecting suspicious process behavior'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver