• DocumentCode
    3715325
  • Title

    Host intrusion detection using system call argument-based clustering combined with Bayesian classification

  • Author

    Oualid Koucham;Tajjeeddine Rachidi;Nasser Assem

  • Author_Institution
    School of Science and Engineering, Al Akhawayn University in Ifrane, Ifrane 53000, Morocco
  • fYear
    2015
  • Firstpage
    1010
  • Lastpage
    1016
  • Abstract
    We deal in this paper with anomaly-based host intrusion detection using system call traces produced by a host´s kernel. In addition to the sequences, we leverage system call arguments, contextual information and domain level knowledge to produce clusters for each individual system call. These clusters are then used to rewrite process sequences of system calls obtained from kernel logs. The new sequences are then fed to a naïve Bayes supervised classifier (SC2.2) that builds class conditional probabilities from Markov modeling of system call sequences. The results of our proposed two-stage (that is clustering followed by classification) intrusion detection system on the 1999 DARPA dataset from the MIT Lincoln Lab show significant performance improvements in terms of false positive rate, while maintaining a high detection rate when compared with other classifiers. The two-stage classifier fares also better than classification alone with SC2.2 on system calls without arguments and contextual knowledge.
  • Keywords
    "Intrusion detection","Hidden Markov models","Measurement","Markov processes","Monitoring","Intelligent systems","Electronic mail"
  • Publisher
    ieee
  • Conference_Titel
    SAI Intelligent Systems Conference (IntelliSys), 2015
  • Type

    conf

  • DOI
    10.1109/IntelliSys.2015.7361267
  • Filename
    7361267