DocumentCode
434563
Title
Profiling program and user behaviors for anomaly intrusion detection based on non-negative matrix factorization
Author
Wang, Wei ; Guan, Xiaohong ; Zhang, Xiangliang
Author_Institution
State Key Lab. for Manuf. Syst., Xi´´an Jiaotong Univ., China
Volume
1
fYear
2004
fDate
14-17 Dec. 2004
Firstpage
99
Abstract
Profiling program and user behaviors is an effective approach for detecting hostile attacks to a computer system. A new model based method by non-negative matrix factorization (NMF) is presented in this paper to profile program and user behaviors for anomaly intrusion detection. In this new method, the audit data streams obtained from sequences of system calls and UNIX commands are used as the information source. The audit data is partitioned into segments with a fixed length. Program and user behaviors are, in turn, measured by the frequencies of individual system calls or commands embedded in each segment of the data, and NMF is applied to extract the features from the blocks of audit data associated with the normal behaviors. The model describing the normal program and user behaviors are built based on these features and deviation from the normal program and user behaviors above a predetermined threshold is considered as anomalous. The method is implemented and tested with the system call data from the University of New Mexico and the Unix command data from AT&T Research lab. Experiment results show that the proposed method is promising in terms of detection accuracy, computational expense and implementation for real-time intrusion detection.
Keywords
Unix; computer networks; matrix decomposition; security of data; UNIX command; anomaly intrusion detection; audit data stream; hostile attack detection; nonnegative matrix factorization; profiling program; real-time intrusion detection; user behaviors; Computer networks; Computer security; Data mining; Electronic mail; Feature extraction; Frequency measurement; Intrusion detection; Laboratories; Monitoring; System testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Decision and Control, 2004. CDC. 43rd IEEE Conference on
ISSN
0191-2216
Print_ISBN
0-7803-8682-5
Type
conf
DOI
10.1109/CDC.2004.1428613
Filename
1428613
Link To Document