DocumentCode :
259718
Title :
An abnormal file access behavior detection approach based on file path diversity
Author :
Xiaobin Wang ; Yonglin Sun ; Yongjun Wang
Author_Institution :
College of Computer, National University of Defense Technology, 410073, Changsha, HuNan Province, China
fYear :
2014
fDate :
15-17 May 2014
Firstpage :
1
Lastpage :
5
Abstract :
Information security is a great challenge for organizations in our modern information world. Existing security facilities like Firewalls, Intrusion Detection Systems and Antivirus are not enough to guarantee the security of information. File is an important carrier of information, which is the intent of quite a number of attackers, in this paper, we propose an FPD-based approach for detecting abnormal file access behaviours. FPD (File Path Diversity) is a quantized value which measures how far a set of file paths is spread out, and in which abnormal file access behaviours and normal ones show significant differences, making it an effective indicator for detecting malicious processes that controlled by attackers to search and steal valuable files. An algorithm of calculating FPD values is presented, as well as a prototype system based on FPD for detecting malicious processes. Experiments demonstrate that FPD is very effective in detecting malicious processes with abnormal file access behaviours, we get a best result of a100% Detection Rate and a 3.85% False Positive Rate.
Keywords :
Information security; abnormal file access behaviours; anomaly detection; file path diversity;
fLanguage :
English
Publisher :
iet
Conference_Titel :
Information and Communications Technologies (ICT 2014), 2014 International Conference on
Conference_Location :
Nanjing, China
Type :
conf
DOI :
10.1049/cp.2014.0632
Filename :
6913685
Link To Document :
بازگشت