Back to Search Start Over

A New Method to Detect Intrusions Using System Calls.

Authors :
PAN Feng
OUYANG Ming-guang
WANG Wei-nong
Source :
Journal of Shanghai Jiao Tong University; Jan2004, Vol. 38 Issue 1, p26-33, 4p
Publication Year :
2004

Abstract

This paper advanced a new algorithm to detect network intrusions using sequences of system calls. This algorithm uses a data structure called weight tree, first it uses normal system call trace to build weight tree forest, which have to be pruned periodically in order to learn new pattern and eliminate impurity. Then it scans abnormal trace using those trees and gets the corresponding weight sequences. Those weight sequences can tell us if something abnormal has happened or not. It acquired good results in experiment. [ABSTRACT FROM AUTHOR]

Details

Language :
Chinese
ISSN :
10087095
Volume :
38
Issue :
1
Database :
Supplemental Index
Journal :
Journal of Shanghai Jiao Tong University
Publication Type :
Academic Journal
Accession number :
67211285