Résumé
This paper addresses the problem of creating patterns that can be used to model the normal behavior of a given process. The models can be used for intrusion-detection purposes. First, we present a novel method to generate input data sets that enable us to observe the normal behavior of a process in a secure environment. Second, we propose various techniques to derive either fixed-length or variable-length patterns from the input data sets. We show the advantages and drawbacks of each technique, based on the results of the experiments we have run on our testbed.
| langue originale | Anglais |
|---|---|
| Pages (de - à) | 159-181 |
| Nombre de pages | 23 |
| journal | Journal of Computer Security |
| Volume | 8 |
| Numéro de publication | 2 |
| Les DOIs | |
| état | Publié - 1 janv. 2000 |
| Modification externe | Oui |
Empreinte digitale
Examiner les sujets de recherche de « Fixed- vs. variable-length patterns for detecting suspicious process behavior ». Ensemble, ils forment une empreinte digitale unique.Contient cette citation
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver