A Multi-Order Markov Chain Based Scheme for Anomaly Detection

被引:11
|
作者
Sha, Wenyao [1 ]
Zhu, Yongxin [1 ]
Huang, Tian [1 ]
Qiu, Meikang [2 ]
Zhu, Yan [1 ]
Zhang, Qiannan [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Microelect, Shanghai 200030, Peoples R China
[2] Univ Kentucky, Dept Elect & Comp Engn, Lexington, KY 40506 USA
来源
2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW) | 2013年
关键词
Markov chain; Kth-order Markov chain; multivariate time series; anomaly detection; COMPUTER AUDIT DATA; INTRUSION-DETECTION; MODEL;
D O I
10.1109/COMPSACW.2013.12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a feasible multi-order Markov chain based scheme for anomaly detection in server systems. In our approach, both the high-order Markov chain and multivariate time series are taken into account, along with the detailed design of training and testing algorithms. To evaluate its effectiveness, the Defense Advanced Research Projects Agency (DARPA) Intrusion Detection Evaluation Data Set is used as stimuli to our model, by which system calls and the corresponding return values form a two-dimensional input set. The calculation result shows that this approach is able to produce several effective indicators of anomalies. In addition to the absolute values given by an individual single-order model, we also notice a novelty unprecedented before, i.e., the changes in ranking positions of outputs from different-order ones also correlate closely with abnormal behaviours. Moreover, the analysis and application proves our approach's efficiency in consuming reasonable cost of time and storage.
引用
收藏
页码:83 / 88
页数:6
相关论文
共 50 条
  • [21] Fault prognostic of electronics based on optimal multi-order particle filter
    Jiang, Yuanyuan
    Wang, Youren
    Wu, Yi
    Sun, Quan
    MICROELECTRONICS RELIABILITY, 2016, 62 : 167 - 177
  • [22] Markov Chain Modeling for Anomaly Detection in High Performance Computing System Logs
    Haque, Abida
    DeLucia, Alexandra
    Baseman, Elisabeth
    HUST'17: PROCEEDINGS OF THE FOURTH INTERNATIONAL WORKSHOP ON HPC USER SUPPORT TOOLS, 2017,
  • [23] Adaptive Anomaly Detection in the Behavior of Computer Systems Users on the Basis of Markov Chains of Variable Order. Part II: Anomaly Detection Methods and Experimental Results
    Kussul, Natalya N.
    Sokolov, Artem M.
    2003, Begell House Inc. (35) : 1 - 5+69
  • [24] Sec-IoV: A Multi-Stage Anomaly Detection Scheme for Internet of Vehicles
    Garg, Sahil
    Kaur, Kuljeet
    Kaddoum, Georges
    Gagnon, Francois
    Kumar, Neeraj
    Han, Zhu
    PROCEEDINGS OF THE 2019 ACM MOBIHOCWORKSHOP ON PERVASIVE SYSTEMS IN THE IOT ERA (PERSIST-IOT '19), 2019, : 37 - 42
  • [25] An Anomaly Detection System based on Hide Markov Model for MANET
    Ye, Xia
    Li, Junshan
    Li, Yanling
    2010 6TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS NETWORKING AND MOBILE COMPUTING (WICOM), 2010,
  • [26] Hidden semi-Markov model for anomaly detection
    Tan, Xiaobin
    Xi, Hongsheng
    APPLIED MATHEMATICS AND COMPUTATION, 2008, 205 (02) : 562 - 567
  • [27] Hidden Markov Based Anomaly Detection for Water Supply Systems
    Zohrevand, Ahra
    Glasser, Uwe
    Shahir, Hamed Yaghoubi
    Tayebi, Mohammad A.
    Costanzo, Robert
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 1551 - 1560
  • [28] Dynamic ACB Scheme Based on Neural Networks and Markov Chain
    Li, Shaofu
    Yang, Liu
    Fan, Pingzhi
    2022 10TH INTERNATIONAL WORKSHOP ON SIGNAL DESIGN AND ITS APPLICATIONS IN COMMUNICATIONS (IWSDA), 2022, : 38 - 42
  • [29] A novel boosting-based anomaly detection scheme
    Tong, HH
    Li, CR
    He, JR
    Tran, QA
    Duan, HX
    Li, X
    PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 3199 - 3203
  • [30] NADSR: A Network Anomaly Detection Scheme Based on Representation
    Liu, Xu
    Di, Xiaoqiang
    Liu, Weiyou
    Zhang, Xingxu
    Qi, Hui
    Li, Jinqing
    Zhao, Jianping
    Yang, Huamin
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT (KSEM 2020), PT I, 2020, 12274 : 380 - 387