TY - GEN
T1 - Learning classifiers for misuse and anomaly detection using a bag of system calls representation
AU - Kang, Dae Ki
AU - Fuller, Doug
AU - Honavar, Vasant
PY - 2005
Y1 - 2005
N2 - In this paper, we propose a "bag of system calls" representation for intrusion detection in system call sequences and describe misuse and anomaly detection results with standard machine learning techniques on University of New Mexico (UNM) and MIT Lincoln Lab (MIT LL) system call sequences with the proposed representation. With the feature representation as input, we compare the performance of several machine learning techniques for misuse detection and show experimental results on anomaly detection. The results show that standard machine learning and clustering techniques on simple "bag of system calls" representation of system call sequences is effective and often performs better than those approaches that use foreign contiguous subsequences in detecting intrusive behaviors of compromised processes.
AB - In this paper, we propose a "bag of system calls" representation for intrusion detection in system call sequences and describe misuse and anomaly detection results with standard machine learning techniques on University of New Mexico (UNM) and MIT Lincoln Lab (MIT LL) system call sequences with the proposed representation. With the feature representation as input, we compare the performance of several machine learning techniques for misuse detection and show experimental results on anomaly detection. The results show that standard machine learning and clustering techniques on simple "bag of system calls" representation of system call sequences is effective and often performs better than those approaches that use foreign contiguous subsequences in detecting intrusive behaviors of compromised processes.
UR - http://www.scopus.com/inward/record.url?scp=33745463455&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=33745463455&partnerID=8YFLogxK
U2 - 10.1109/IAW.2005.1495942
DO - 10.1109/IAW.2005.1495942
M3 - Conference contribution
AN - SCOPUS:33745463455
SN - 0780392906
SN - 9780780392908
T3 - Proceedings from the 6th Annual IEEE System, Man and Cybernetics Information Assurance Workshop, SMC 2005
SP - 118
EP - 125
BT - Proceedings from the Sixth Annual IEEE System, Man and Cybernetics Information Assurance Workshop, SMC 2005
T2 - 6th Annual IEEE System, Man and Cybernetics Information Assurance Workshop, SMC 2005
Y2 - 15 June 2005 through 17 June 2005
ER -