• DocumentCode
    2359801
  • Title

    Temporal signatures for intrusion detection

  • Author

    Jones, Anita ; Li, Song

  • fYear
    2001
  • fDate
    10-14 Dec. 2001
  • Firstpage
    252
  • Lastpage
    261
  • Abstract
    We introduce a new method for detecting intrusions based on the temporal behavior of applications. It builds on an existing method of application intrusion detection developed at the University of New Mexico that uses a system call sequence as a signature. Intrusions are detected by comparing the signature of the intrusion and that of the normal application. But when the system call sequences generated by the intrusion and the normal application are sufficiently similar, this method cannot work. By extending system call signature to incorporate temporal information related to the application, we form a richer signature. Analysis shows that the temporal behavior for many applications is relatively stable. We exclude high variance data when creating a normal database to characterize an application with a temporal signature. It can then be the basis for future comparisons in an intrusion detection system. This paper discusses experiments that test the effectiveness of the temporal signature on different applications, alternative intrusions, and in various environments. The results show that by choosing appropriate analysis methods and experimentally adjusting the parameters, intrusions are readily detected. Finally, we give some comparisons between the temporal signature method and the system call method.
  • Keywords
    security of data; system monitoring; temporal logic; applications; call sequence as signature; intrusion detection; system call method; temporal behavior; temporal information; temporal signatures; Application software; Buffer overflow; Computer crime; Databases; Intrusion detection; Monitoring; Operating systems; Security; Testing; Time measurement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual
  • Print_ISBN
    0-7695-1405-7
  • Type

    conf

  • DOI
    10.1109/ACSAC.2001.991541
  • Filename
    991541