Intrusion Prediction with System-call Sequence-to-Sequence Model

08/06/2018
by   ShaoHua Lv, et al.
0

The advanced development of the Internet facilitates efficient information exchange while also been exploited by adversaries. Intrusion detection system (IDS) as an important defense component of network security has always been widely studied in security research. However, research on intrusion prediction, which is more critical for network security, is received less attention. We argue that the advanced anticipation and timely impede of invasion is more vital than simple alarms in security defenses. General research methods regarding prediction are analyzing short term of system-calls to predict forthcoming abnormal behaviors. In this paper we take advantages of the remarkable performance of recurrent neural networks (RNNs) in dealing with long sequential problem, introducing the sequence-to-sequence model into our intrusion prediction work. By semantic modeling system-calls we build a robust system-call sequence-to-sequence prediction model. With taking the system-call traces invoked during the program running as known prerequisite, our model predicts sequence of system-calls that is most likely to be executed in a near future period of time that enabled the ability of monitoring system status and prophesying the intrusion behaviors. Our experiments show that the predict method proposed in this paper achieved well prediction performance on ADFALD intrusion detection test data set. Moreover, the predicted sequence, combined with the known invoked traces of system, significantly improves the performance of intrusion detection verified on various classifiers.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/24/2021

SCADS: A Scalable Approach Using Spark in Cloud for Host-based Intrusion Detection System with System Calls

Following the current big data trend, the scale of real-time system call...
research
09/24/2017

Intrusions in Marked Renewal Processes

We present a probabilistic model of an intrusion in a marked renewal pro...
research
10/13/2014

Proceedings 2014 International Workshop on Advanced Intrusion Detection and Prevention

This volume contains the proceedings of the 2014 International Advanced ...
research
04/15/2019

Comparison of System Call Representations for Intrusion Detection

Over the years, artificial neural networks have been applied successfull...
research
01/16/2014

Intrusion Detection using Continuous Time Bayesian Networks

Intrusion detection systems (IDSs) fall into two high-level categories: ...
research
10/06/2020

Interpretable Sequence Classification via Discrete Optimization

Sequence classification is the task of predicting a class label given a ...
research
06/26/2023

Ensemble of Random and Isolation Forests for Graph-Based Intrusion Detection in Containers

We propose a novel solution combining supervised and unsupervised machin...

Please sign up or login with your details

Forgot password? Click here to reset