Skip to main content

Behavioral distance for intrusion detection

Publication ,  Conference
Gao, D; Reiter, MK; Song, D
Published in: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
January 1, 2006

We introduce a notion, behavioral distance, for evaluating the extent to which processes - potentially running different programs and executing on different platforms - behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead. © Springer-Verlag Berlin Heidelberg 2006.

Duke Scholars

Published In

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

DOI

EISSN

1611-3349

ISSN

0302-9743

Publication Date

January 1, 2006

Volume

3858 LNCS

Start / End Page

63 / 81

Related Subject Headings

  • Artificial Intelligence & Image Processing
  • 46 Information and computing sciences
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Gao, D., Reiter, M. K., & Song, D. (2006). Behavioral distance for intrusion detection. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 3858 LNCS, pp. 63–81). https://doi.org/10.1007/11663812_4
Gao, D., M. K. Reiter, and D. Song. “Behavioral distance for intrusion detection.” In Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 3858 LNCS:63–81, 2006. https://doi.org/10.1007/11663812_4.
Gao D, Reiter MK, Song D. Behavioral distance for intrusion detection. In: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). 2006. p. 63–81.
Gao, D., et al. “Behavioral distance for intrusion detection.” Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), vol. 3858 LNCS, 2006, pp. 63–81. Scopus, doi:10.1007/11663812_4.
Gao D, Reiter MK, Song D. Behavioral distance for intrusion detection. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). 2006. p. 63–81.

Published In

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

DOI

EISSN

1611-3349

ISSN

0302-9743

Publication Date

January 1, 2006

Volume

3858 LNCS

Start / End Page

63 / 81

Related Subject Headings

  • Artificial Intelligence & Image Processing
  • 46 Information and computing sciences