<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="https://ahls.dorsal.polymtl.ca"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Automated monitoring and debugging of large scale manycore heterogeneous systems - Kernel State Modules</title>
 <link>https://ahls.dorsal.polymtl.ca/taxonomy/term/30</link>
 <description></description>
 <language>en</language>
<item>
 <title>A Host-based Anomaly Detection Approach by Representing System Calls as States of Kernel Modules</title>
 <link>https://ahls.dorsal.polymtl.ca/node/114</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;S. S. Murtaza, W. Khreich, A. Hamou-Lhadj, M. Couture , &quot;A Host-based Anomaly Detection Approach by Representing System Calls as States of Kernel Modules,&quot; In Proc. of the 24th IEEE International Symposium on Software Reliability Engineering (ISSRE), Pasadena, CA, USA, 2013.&lt;/p&gt;
&lt;p&gt;Despite over two decades of research, high false alarm rates, large trace sizes and high processing times remain among the key issues in host-based anomaly intrusion detection systems. In an attempt to reduce the false alarm rate and processing time while increasing the detection rate, this paper presents a novel anomaly detection technique based on semantic interactions of system calls. The key concept is to represent system calls as states of kernel modules, analyze the state interactions, and identify anomalies by comparing the probabilities of occurrences of states in normal and anomalous traces. In addition, the proposed technique allows a visual understanding of system behaviour, and hence a more informed decision making. We evaluated this technique on Linux based programs of UNM datasets and a new modern Firefox dataset. We created the Firefox dataset on Linux using contemporary test suites and hacking techniques. The results show that our technique yields fewer false alarms and can handle large traces with smaller (or comparable) processing times compared against the existing techniques for the host based anomaly intrusion detection systems.&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-tags field-type-taxonomy-term-reference field-label-above clearfix&quot;&gt;&lt;h3 class=&quot;field-label&quot;&gt;Tags: &lt;/h3&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li class=&quot;taxonomy-term-reference-0&quot; rel=&quot;dc:subject&quot;&gt;&lt;a href=&quot;/taxonomy/term/28&quot; typeof=&quot;skos:Concept&quot; property=&quot;rdfs:label skos:prefLabel&quot; datatype=&quot;&quot;&gt;HIDS&lt;/a&gt;&lt;/li&gt;&lt;li class=&quot;taxonomy-term-reference-1&quot; rel=&quot;dc:subject&quot;&gt;&lt;a href=&quot;/taxonomy/term/29&quot; typeof=&quot;skos:Concept&quot; property=&quot;rdfs:label skos:prefLabel&quot; datatype=&quot;&quot;&gt;System calls&lt;/a&gt;&lt;/li&gt;&lt;li class=&quot;taxonomy-term-reference-2&quot; rel=&quot;dc:subject&quot;&gt;&lt;a href=&quot;/taxonomy/term/30&quot; typeof=&quot;skos:Concept&quot; property=&quot;rdfs:label skos:prefLabel&quot; datatype=&quot;&quot;&gt;Kernel State Modules&lt;/a&gt;&lt;/li&gt;&lt;li class=&quot;taxonomy-term-reference-3&quot; rel=&quot;dc:subject&quot;&gt;&lt;a href=&quot;/taxonomy/term/31&quot; typeof=&quot;skos:Concept&quot; property=&quot;rdfs:label skos:prefLabel&quot; datatype=&quot;&quot;&gt;Computer Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description>
 <pubDate>Wed, 13 Nov 2013 22:29:02 +0000</pubDate>
 <dc:creator>ahamou-lhadj</dc:creator>
 <guid isPermaLink="false">114 at https://ahls.dorsal.polymtl.ca</guid>
</item>
</channel>
</rss>
