Intrusion Detection with Support Vector Machines and Generative Models

Loading...
Thumbnail Image

Files

TR_2002-22.pdf (200.85 KB)
No. of downloads: 862

Publication or External Link

Date

2002

Citation

DRUM DOI

Abstract

This paper addresses the task of detecting intrusions in the form of malicious programs on a host computer system by inspecting the trace of system calls made by these programs. We use "attack-tree" type generative models for such intrusions to select features that are used by a Support Vector Machine Classifier. Our approach combines the ability of an HMM generative model to handle variable-length strings, i.e. the traces, and the non-asymptotic nature of Support Vector Machines that permits them to work well with small training sets.

Notes

Rights