DocumentCode :
77174
Title :
An OS-level Framework for Anomaly Detection in Complex Software Systems
Author :
Bovenzi, Antonio ; Brancati, Francesco ; Russo, Stefano ; Bondavalli, Andrea
Author_Institution :
Dipt. di Ing. Elettr. e delle Tecnol. dell´Inf., Univ. di Napoli Federico II, Naples, Italy
Volume :
12
Issue :
3
fYear :
2015
fDate :
May-June 1 2015
Firstpage :
366
Lastpage :
372
Abstract :
Revealing anomalies at the operating system (OS) level to support online diagnosis activities of complex software systems is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) are inadequate or cannot be applied. In this paper we propose a configurable detection framework to reveal anomalies in the OS behavior, related to system misbehaviors. The detector is based on online statistical analyses techniques, and it is designed for systems that operate under variable and non-stationary conditions. The framework is evaluated to detect the activation of software faults in a complex distributed system for Air Traffic Management (ATM). Results of experiments with two different OSs, namely Linux Red Hat EL5 and Windows Server 2008, show that the detector is effective for mission-critical systems. The framework can be configured to select the monitored indicators so as to tune the level of intrusivity. A sensitivity analysis of the detector parameters is carried out to show their impact on the performance and to give to practitioners guidelines for its field tuning.
Keywords :
operating systems (computers); software fault tolerance; statistical analysis; Linux Red Hat EL5; OS-level framework; Windows Server 2008; air traffic management; anomaly detection; complex distributed system; complex software systems; configurable detection framework; mission-critical systems; online statistical analysis techniques; operating system level; Detectors; Linux; Monitoring; Operating systems; Probes; Software systems; Anomaly-detection; mission-critical systems; operating system; system monitoring;
fLanguage :
English
Journal_Title :
Dependable and Secure Computing, IEEE Transactions on
Publisher :
ieee
ISSN :
1545-5971
Type :
jour
DOI :
10.1109/TDSC.2014.2334305
Filename :
6847216
Link To Document :
بازگشت