Passer à la navigation principale Passer à la recherche Passer au contenu principal

Fixed- vs. variable-length patterns for detecting suspicious process behavior

  • S.

Résultats de recherche: Contribution à un journalArticleRevue par des pairs

Résumé

This paper addresses the problem of creating patterns that can be used to model the normal behavior of a given process. The models can be used for intrusion-detection purposes. First, we present a novel method to generate input data sets that enable us to observe the normal behavior of a process in a secure environment. Second, we propose various techniques to derive either fixed-length or variable-length patterns from the input data sets. We show the advantages and drawbacks of each technique, based on the results of the experiments we have run on our testbed.

langue originaleAnglais
Pages (de - à)159-181
Nombre de pages23
journalJournal of Computer Security
Volume8
Numéro de publication2
Les DOIs
étatPublié - 1 janv. 2000
Modification externeOui

Empreinte digitale

Examiner les sujets de recherche de « Fixed- vs. variable-length patterns for detecting suspicious process behavior ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation