Int J Performability Eng ›› 2018, Vol. 14 ›› Issue (2): 300-309.doi: 10.23940/ijpe.18.02.p11.300309

• Original articles • Previous Articles     Next Articles

Intrusion Anomaly Detection based on Sequence

Gangyue Lei   

  1. Hunan College of Information, ChangSha, 410200, China

Abstract:

For single event sequences, a new anomaly detection method based on SV-LFSP (Short Variable-Length Frequent Sequence Pattern) is presented in this paper. Considering the structure character of procedure calling sequences generated by computer programs, the method defines SV-LFSP and contains three fundamental elements in the program flow, sequence, iteration and selection. To build the SV-LFSP library, the SV-LFSP generation algorithm is used. Essentially, this algorithm follows the idea of TEIRESIAS, with an additional redundancy controlling mechanism. Event flow chart, which has the capability of describing program behavior accurately, is a visual version of the SV-LFSP library. This new method is superior to previously provided frequent episode pattern matching algorithms for compact detection models, with high detection efficiency and low time delays.