Authors
Wenke Lee, Salvatore J Stolfo, Philip K Chan
Publication date
1997/7/27
Journal
AAAI workshop on AI approaches to fraud detection and risk management
Pages
50-56
Description
In this paper we describe our preliminary experiments to extend the work pioneered by Forrest (see Forrest et al. 1996) on learning the (normal abnormal) patterns of Unix processes. These patterns can be used to identify misuses of and intrusions in Unix systems. We formulated machine learning tasks on operating system call sequences of normal and abnormal (intrusion) executions of the Unix sendmail program. We show that our methods can accurately distinguish all abnormal executions of sendmail from the normal ones provided in a set of test traces. These preliminary results indicate that machine learning can play an important role by generalizing stored sequence information to perhaps provide broader intrusion detection services. The experiments also reveal some interesting and challenging problems for future research. much effort has been devoted to the problem of detecting intrusions as quickly as possible.
Total citations
1998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242616142329295040363127232319291917171313171113412
Scholar articles
W Lee, SJ Stolfo, PK Chan - AAAI workshop on AI approaches to fraud detection …, 1997