Back to Search
Start Over
A New Method to Detect Intrusions Using System Calls.
- Source :
- Journal of Shanghai Jiao Tong University; Jan2004, Vol. 38 Issue 1, p26-33, 4p
- Publication Year :
- 2004
-
Abstract
- This paper advanced a new algorithm to detect network intrusions using sequences of system calls. This algorithm uses a data structure called weight tree, first it uses normal system call trace to build weight tree forest, which have to be pruned periodically in order to learn new pattern and eliminate impurity. Then it scans abnormal trace using those trees and gets the corresponding weight sequences. Those weight sequences can tell us if something abnormal has happened or not. It acquired good results in experiment. [ABSTRACT FROM AUTHOR]
Details
- Language :
- Chinese
- ISSN :
- 10087095
- Volume :
- 38
- Issue :
- 1
- Database :
- Supplemental Index
- Journal :
- Journal of Shanghai Jiao Tong University
- Publication Type :
- Academic Journal
- Accession number :
- 67211285