A Multi-Order Markov Chain Based Scheme for Anomaly Detection

被引:11
作者
Sha, Wenyao [1 ]
Zhu, Yongxin [1 ]
Huang, Tian [1 ]
Qiu, Meikang [2 ]
Zhu, Yan [1 ]
Zhang, Qiannan [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Microelect, Shanghai 200030, Peoples R China
[2] Univ Kentucky, Dept Elect & Comp Engn, Lexington, KY 40506 USA
来源
2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW) | 2013年
关键词
Markov chain; Kth-order Markov chain; multivariate time series; anomaly detection; COMPUTER AUDIT DATA; INTRUSION-DETECTION; MODEL;
D O I
10.1109/COMPSACW.2013.12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a feasible multi-order Markov chain based scheme for anomaly detection in server systems. In our approach, both the high-order Markov chain and multivariate time series are taken into account, along with the detailed design of training and testing algorithms. To evaluate its effectiveness, the Defense Advanced Research Projects Agency (DARPA) Intrusion Detection Evaluation Data Set is used as stimuli to our model, by which system calls and the corresponding return values form a two-dimensional input set. The calculation result shows that this approach is able to produce several effective indicators of anomalies. In addition to the absolute values given by an individual single-order model, we also notice a novelty unprecedented before, i.e., the changes in ranking positions of outputs from different-order ones also correlate closely with abnormal behaviours. Moreover, the analysis and application proves our approach's efficiency in consuming reasonable cost of time and storage.
引用
收藏
页码:83 / 88
页数:6
相关论文
共 50 条
  • [41] An Intrusion Detection Scheme Based on Anomaly Mining in Internet of Things
    Fu, Rongrong
    Zheng, Kangfeng
    Zhang, Dongmei
    Yang, Yixian
    2011 IET 4TH INTERNATIONAL CONFERENCE ON WIRELESS, MOBILE & MULTIMEDIA NETWORKS (ICWMMN 2011), 2011, : 315 - 320
  • [42] A Distributed Anomaly Detection Scheme Based on Correlation Awareness in WSN
    Zhongmin Wang
    Rui Gao
    Cong Gao
    Yanping Chen
    Fengwei Wang
    Wireless Personal Communications, 2024, 134 : 519 - 541
  • [43] A Distributed Anomaly Detection Scheme Based on Correlation Awareness in WSN
    Wang, Zhongmin
    Gao, Rui
    Gao, Cong
    Chen, Yanping
    Wang, Fengwei
    WIRELESS PERSONAL COMMUNICATIONS, 2024, 134 (01) : 519 - 541
  • [44] Network anomaly detection based on probabilistic analysis
    Park, JinSoo
    Choi, Dong Hag
    Jeon, You-Boo
    Nam, Yunyoung
    Hong, Min
    Park, Doo-Soon
    SOFT COMPUTING, 2018, 22 (20) : 6621 - 6627
  • [45] A novel forecasting method based on multi-order fuzzy time series and technical analysis
    Ye, Furong
    Zhang, Liming
    Zhang, Defu
    Fujita, Hamido
    Gong, Zhiguo
    INFORMATION SCIENCES, 2016, 367 : 41 - 57
  • [46] A hybrid high-order Markov chain model for computer intrusion detection
    Ju, WH
    Vardi, Y
    JOURNAL OF COMPUTATIONAL AND GRAPHICAL STATISTICS, 2001, 10 (02) : 277 - 295
  • [47] A Method for Aero-Engine Gas Path Anomaly Detection Based on Markov Transition Field and Multi-LSTM
    Cui, Langfu
    Zhang, Chaoqi
    Zhang, Qingzhen
    Wang, Junle
    Wang, Yixuan
    Shi, Yan
    Lin, Cong
    Jin, Yang
    AEROSPACE, 2021, 8 (12)
  • [48] Economic forecast based on Markov chain
    Tian, Jiya
    Zhang, Yong
    Li, Nan
    PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON ELECTRICAL & ELECTRONICS ENGINEERING AND COMPUTER SCIENCE (ICEEECS 2016), 2016, 50 : 908 - 914
  • [49] Anomaly Detection Based on Multi-Attribute Decision
    Zeng, QingPeng
    Wu, ShuiXiu
    PROCEEDINGS OF THE 2009 WRI GLOBAL CONGRESS ON INTELLIGENT SYSTEMS, VOL II, 2009, : 394 - +
  • [50] A first order Markov chain based model for flat fading channel
    Saadani, A
    Tortelier, P
    13TH IEEE INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS, VOL 1-5, PROCEEDINGS: SAILING THE WAVES OF THE WIRELESS OCEANS, 2002, : 1636 - 1639