DocumentCode :
2885446
Title :
Combining Hidden Markov Models for Improved Anomaly Detection
Author :
Khreich, Wael ; Granger, Eric ; Sabourin, Robert ; Miri, Ali
Author_Institution :
Lab. d´´Imagerie, de Vision et d´´Intell. Artificielle (LIVIA), Ecole de Technol. Super., Montreal, QC, Canada
fYear :
2009
fDate :
14-18 June 2009
Firstpage :
1
Lastpage :
6
Abstract :
In host-based intrusion detection systems (HIDS), anomaly detection involves monitoring for significant deviations from normal system behavior. Hidden Markov Models (HMMs) have been shown to provide a high level performance for detecting anomalies in sequences of system calls to the operating system kernel. Although the number of hidden states is a critical parameter for HMM performance, it is often chosen heuristically or empirically, by selecting the single value that provides the best performance on training data. However, this single best HMM does not typically provide a high level of performance over the entire detection space. This paper presents a multiple-HMMs approach, where each HMM is trained using a different number of hidden states, and where HMM responses are combined in the receiver operating characteristics (ROC) space according to the maximum realizable ROC (MRROC) technique. The performance of this approach is compared favorably to that of a single best HMM and to a traditional sequence matching technique called STIDE, using different synthetic HIDS data sets. Results indicate that this approach provides a higher level of performance over a wide range of training set sizes with various alphabet sizes and irregularity indices, and different anomaly sizes, without a significant computational and storage overhead.
Keywords :
hidden Markov models; operating system kernels; security of data; HIDS; HMM; anomaly detection; hidden Markov model; host-based intrusion detection system; maximum realizable ROC technique; operating system kernel; receiver operating characteristics; system call; Communications Society; Computerized monitoring; Event detection; Hidden Markov models; Information technology; Intrusion detection; Kernel; Operating systems; Paper technology; Training data;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, 2009. ICC '09. IEEE International Conference on
Conference_Location :
Dresden
ISSN :
1938-1883
Print_ISBN :
978-1-4244-3435-0
Electronic_ISBN :
1938-1883
Type :
conf
DOI :
10.1109/ICC.2009.5198832
Filename :
5198832
Link To Document :
بازگشت