• DocumentCode
    1944359
  • Title

    The Evolution of System-Call Monitoring

  • Author

    Forrest, Stephanie ; Hofmeyr, Steven ; Somayaji, Anil

  • Author_Institution
    Dept. of Comput. Sci., Univ. of New Mexico, Albuquerque, NM
  • fYear
    2008
  • fDate
    8-12 Dec. 2008
  • Firstpage
    418
  • Lastpage
    430
  • Abstract
    Computer security systems protect computers and networks from unauthorized use by external agents and insiders. The similarities between computer security and the problem of protecting a body against damage from externally and internally generated threats are compelling and were recognized as early as 1972 when the term computer virus was coined. The connection to immunology was made explicit in the mid 1990s, leading to a variety of prototypes, commercial products, attacks, and analyses. The paper reviews one thread of this active research area, focusing on system-call monitoring and its application to anomaly intrusion detection and response. The paper discusses the biological principles illustrated by the method, followed by a brief review of how system call monitoring was used in anomaly intrusion detection and the results that were obtained. Proposed attacks against the method are discussed, along with several important branches of research that have arisen since the original papers were published. These include other data modeling methods, extensions to the original system call method, and rate limiting responses. Finally, the significance of this body of work and areas of possible future investigation are outlined in the conclusion.
  • Keywords
    security of data; system monitoring; anomaly intrusion detection; computer security systems; system-call monitoring; Application software; Computer networks; Computer security; Computerized monitoring; Evolution (biology); Immune system; Intrusion detection; Protection; Prototypes; Yarn;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2008. ACSAC 2008. Annual
  • Conference_Location
    Anaheim, CA
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3447-3
  • Type

    conf

  • DOI
    10.1109/ACSAC.2008.54
  • Filename
    4721577