A Multi-Order Markov Chain Based Scheme for Anomaly Detection

被引:11
|
作者
Sha, Wenyao [1 ]
Zhu, Yongxin [1 ]
Huang, Tian [1 ]
Qiu, Meikang [2 ]
Zhu, Yan [1 ]
Zhang, Qiannan [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Microelect, Shanghai 200030, Peoples R China
[2] Univ Kentucky, Dept Elect & Comp Engn, Lexington, KY 40506 USA
来源
2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW) | 2013年
关键词
Markov chain; Kth-order Markov chain; multivariate time series; anomaly detection; COMPUTER AUDIT DATA; INTRUSION-DETECTION; MODEL;
D O I
10.1109/COMPSACW.2013.12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a feasible multi-order Markov chain based scheme for anomaly detection in server systems. In our approach, both the high-order Markov chain and multivariate time series are taken into account, along with the detailed design of training and testing algorithms. To evaluate its effectiveness, the Defense Advanced Research Projects Agency (DARPA) Intrusion Detection Evaluation Data Set is used as stimuli to our model, by which system calls and the corresponding return values form a two-dimensional input set. The calculation result shows that this approach is able to produce several effective indicators of anomalies. In addition to the absolute values given by an individual single-order model, we also notice a novelty unprecedented before, i.e., the changes in ranking positions of outputs from different-order ones also correlate closely with abnormal behaviours. Moreover, the analysis and application proves our approach's efficiency in consuming reasonable cost of time and storage.
引用
收藏
页码:83 / 88
页数:6
相关论文
共 50 条
  • [1] Statistical Learning for Anomaly Detection in Cloud Server Systems: A Multi-Order Markov Chain Framework
    Sha, Wenyao
    Zhu, Yongxin
    Chen, Min
    Huang, Tian
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2018, 6 (02) : 401 - 413
  • [2] Improvement of protocol anomaly detection based on Markov chain and its application
    Qin, Z
    Li, N
    Zhang, DF
    Bian, NZ
    PARALLEL AND DISTRIBUTED PROCESSING AND APPLICATIONS - ISPA 2005 WORKSHOPS, 2005, 3759 : 387 - 396
  • [3] Sequence Comparison using Multi-Order Markov Chains
    Fang, Xiang
    Lu, Guoqing
    Zhang, Shunpu
    2010 4TH INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICAL ENGINEERING (ICBBE 2010), 2010,
  • [4] Anomaly Detection Boundary Based on the Moving Averages of Markov Chain Model
    Chen, Deqiang
    2015 12th International Conference on Fuzzy Systems and Knowledge Discovery (FSKD), 2015, : 1532 - 1536
  • [5] Multi-order feature interaction-aware intrusion detection scheme for ensuring cyber security of intelligent connected vehicles
    Gong, Weifeng
    Yang, Shichun
    Guang, Haoran
    Ma, Bin
    Zheng, Bowen
    Shi, Yi
    Li, Baotian
    Cao, Yaoguang
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 135
  • [6] Markov Chain-Based Feature Extraction for Anomaly Detection in Time Series and Its Industrial Application
    Zang, Dong
    Liu, Jinhai
    Wang, Huaizhen
    PROCEEDINGS OF THE 30TH CHINESE CONTROL AND DECISION CONFERENCE (2018 CCDC), 2018, : 1059 - 1063
  • [7] A self-adaptive point-of-interest recommendation algorithm based on a multi-order Markov model
    Liu, Shudong
    Wang, Lei
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 89 : 506 - 514
  • [8] Anomaly detection of user behavior based on shell commands and homogeneous Markov chains
    Xinguang, Tian
    Miyi, Duan
    Wenfa, Li
    Chunlai, Sun
    CHINESE JOURNAL OF ELECTRONICS, 2008, 17 (02): : 231 - 236
  • [9] Anomaly detection of program behaviors based on system calls and homogeneous Markov chain models
    Tian, Xinguang
    Gao, Lizhi
    Sun, Chunlai
    Zhang, Eryang
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2007, 44 (09): : 1538 - 1544
  • [10] Research on Markov chain model for system call anomaly detection
    Qian, Q
    Wang, XF
    PROCEEDINGS OF THE 8TH JOINT CONFERENCE ON INFORMATION SCIENCES, VOLS 1-3, 2005, : 328 - 333