16th Annual Computer Security Applications Conference (ACSAC'00)
Two state-based approaches to program-based anomaly detection
New Orleans, Louisiana
December 11-December 15
ISBN: 0-7695-0859-6
This paper describes two intrusion detection algorithms, and gives experimental results on their performance. The algorithms detect anomalies in execution audit data. One is a simply constructed finite-state machine, and the other monitors statistical deviations from normal program behavior. The performance of these algorithms is evaluated as a function of the amount of available training data, and they are compared to the well-known intrusion detection technique of looking for novel n-grams in computer audit data.
Index Terms:
security of data; software performance evaluation; auditing; finite state machines; state-based approaches; program-based anomaly detection; intrusion detection algorithms; experimental results; algorithm performance; execution audit data; finite-state machine; statistical deviation monitoring; n-grams
Citation:
C.C. Michael, A. Ghosh, "Two state-based approaches to program-based anomaly detection," acsac, pp.21, 16th Annual Computer Security Applications Conference (ACSAC'00), 2000