2004Unpublished venueRequires access

An adaptive real-time intrusion detection system using sequences of system call

Kaining Lu, Zehua Chen, Zhigang Jin, Jichang Guo

Open publisher page 10 citations

Abstract

Intrusion detection is the process of monitoring computer networks and systems for violations of security policy. IDS may be of the network (NIDS) or host (HIDS) type. Traditionally, NIDS is the only way of preventing intrusion before an intrusion occurs through analyzing data packages, but has higher false rates. Although with lower false rates, HIDS detects anomalous actions by auditing host system logs that means the intrusion has took place. In this paper, we present one collaborate IDS module to make a real-time detection and block intrusions before occurrences, based on HIDS using sequences of system call anomaly detection.

About this research paper

What this paper is about

Intrusion detection is the process of monitoring computer networks and systems for violations of security policy. IDS may be of the network (NIDS) or host (HIDS) type. Traditionally, NIDS is the only way of preventing intrusion before an intrusion occurs through analyzing data packages, but has higher false rates. Although with lower false rates, HIDS detects anomalous actions by auditing host system logs that means the intrusion has took place. In this paper, we present one collaborate IDS module to make a real-time detection and block intrusions before occurrences, based on HIDS using sequences of system call anomaly detection.

Why it matters

OpenAlex reports 10 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Intrusion detection is the process of monitoring computer networks and systems for violations of security policy. IDS may be of the network (NIDS) or host (HIDS) type. Traditionally, NIDS is the only way of preventing intrusion before an intrusion occurs through analyzing data packages, but has higher false rates. Although with lower false rates, HIDS detects anomalous actions by auditing host system logs that means the intrusion has took place. In this paper, we present one collaborate IDS module to make a real-time detection and block intrusions before occurrences, based on HIDS using sequences of system call anomaly detection.

Key concepts: Intrusion detection system, Computer science, Host-based intrusion detection system, Anomaly-based intrusion detection system, System call, Host (biology), Anomaly detection, Network security

Related papers

Back to paper searchBrowse research topicsOriginal source
An adaptive real-time intrusion detection system using sequences of system call — Research Paper | ScholarLens