DSpace
 

Tai Nguyen So - Vietnam National University, Ha Noi - VNU >
ĐHQGHN - TẠP CHÍ KHOA HỌC >
KHOA HỌC TỰ NHIÊN VÀ CÔNG NGHỆ - NATURAL SCIENCES AND TECHNOLOGY >
NĂM 2008 >
Vol. 24, No.2 >

Search

Please use this identifier to cite or link to this item: http://tainguyenso.vnu.edu.vn/jspui/handle/123456789/310

Title: A program anomaly intrusion detection scheme based on fuzzy inference
Authors: Hoang, Dau Xuan
Nguyen, Minh Ngoc
Keywords: anomaly intrusion detection
fuzzy logic
hidden Markov model
program-based anomaly intrusion detection
Issue Date: 2008
Publisher: ĐHQGHN
Citation: VNU Journal of Science, Natural Sciences and Technology 24 (2008) 71-81
Abstract: A major problem of existing anomaly intrusion detection approaches is that they tend to produce excessive false alarms. One reason for this is that the normal and abnormal behaviour of a monitored object can overlap or be very close to each other, which makes it difficult to define a clear boundary between the two. In this paper, we present a fuzzy-based scheme for program anomaly intrusion detection using system calls. Instead of using crisp conditions, or fixed thresholds, fuzzy sets are used to represent the parameter space of the program sequences of system calls. In addition, fuzzy rules are used to combine multiple parameters of each sequence, using fuzzy reasoning, in order to determine the sequence status. Experimental results showed that the proposed fuzzy-based detection scheme reduced false positive alarms by 48%, compared to the normal database scheme.
URI: http://hdl.handle.net/123456789/310
ISSN: 0866-8612
Appears in Collections:Vol. 24, No.2

Files in This Item:

File Description SizeFormat
b1.pdf212.58 kBAdobe PDFView/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

 

Valid XHTML 1.0! DSpace Software Copyright © 2002-2010  Duraspace - Feedback