Database Group Leipzig (https://old.dbs.uni-leipzig.de)

Intrusion Detection on System Call Graphs

PDF [1]
further information [2]
Google Scholar [3]
publication icon [4]Grimmer, Martin [5]; Röhling, Martin Max [6]; Kricke, Matthias [7]; Franczyk, Bogdan [8]; Rahm, Erhard [9]
Intrusion Detection on System Call Graphs [10]
25. DFN-Konferenz "Sicherheit in vernetzten Systemen"
2018 [11]

Further information: https://www.dfn-cert.de/veranstaltungen/Sicherheitskonferenz2018.html [12]

Description

Cyber attacks such as ransomware can do great damage. Intrusion detection systems can help to detect those attacks. Especially with anomaly detection methods, it is possible to detect previous unknown attacks. In this paper, we present a graph-based approach in combination with existing methods trying to increase recognition rates and reduce false alarm rates. Our Hypotheses: By taking the inherent structure of the underlying data into account, it is possible to gain more insights compared to other known methods. The modern ADFA-LD dataset was used for the evaluation, which reflects the operation in a modern operating system. Compared to the Stide approach we demonstrate that a graph-based approach can keep pace.

AttachmentSize
Intrusion-Detection-on-System-Call-Graphs.pdf [13]436.06 KB

Source URL:
https://old.dbs.uni-leipzig.de/en/publication/title/intrusion_detection_on_system_call_graphs