Matches in SemOpenAlex for { <https://semopenalex.org/work/W1566884194> ?p ?o ?g. }
- W1566884194 abstract "High false alarm rates and execution times are among the key issues in host-based anomaly detection systems. In this paper, we investigate the use of trace abstraction techniques for reducing the execution time of anomaly detectors while keeping the same accuracy. The key idea is to represent system call traces as traces of kernel module interactions and use the resulting abstract traces as input to known anomaly detection techniques, such as STIDE (the Sequence Time-Delay Embedding) and HMM (Hidden Markov Models). We performed experiments on three datasets, namely, the traditional UNM dataset as well as two modern datasets, Firefox and ADFA-LD. The results show that kernel module traces can lead to similar or fewer false alarms and considerably smaller execution times compared to raw system call traces for host-based anomaly detection systems." @default.
- W1566884194 created "2016-06-24" @default.
- W1566884194 creator A5032967266 @default.
- W1566884194 creator A5035349718 @default.
- W1566884194 creator A5058884064 @default.
- W1566884194 creator A5079136654 @default.
- W1566884194 date "2015-05-01" @default.
- W1566884194 modified "2023-09-27" @default.
- W1566884194 title "A trace abstraction approach for host-based anomaly detection" @default.
- W1566884194 cites W1496741998 @default.
- W1566884194 cites W1941427975 @default.
- W1566884194 cites W1981738628 @default.
- W1566884194 cites W1993943803 @default.
- W1566884194 cites W2006862475 @default.
- W1566884194 cites W2007087405 @default.
- W1566884194 cites W2046255282 @default.
- W1566884194 cites W2055510056 @default.
- W1566884194 cites W2085305295 @default.
- W1566884194 cites W2093488494 @default.
- W1566884194 cites W2095979141 @default.
- W1566884194 cites W2100533862 @default.
- W1566884194 cites W2101899163 @default.
- W1566884194 cites W2106442760 @default.
- W1566884194 cites W2118372007 @default.
- W1566884194 cites W2118528519 @default.
- W1566884194 cites W2125838338 @default.
- W1566884194 cites W2129860818 @default.
- W1566884194 cites W2135143063 @default.
- W1566884194 cites W2139731313 @default.
- W1566884194 cites W2147191819 @default.
- W1566884194 cites W2148324316 @default.
- W1566884194 cites W2152955798 @default.
- W1566884194 cites W2161085373 @default.
- W1566884194 cites W2164219553 @default.
- W1566884194 cites W2166855330 @default.
- W1566884194 cites W3136767761 @default.
- W1566884194 cites W4229772528 @default.
- W1566884194 doi "https://doi.org/10.1109/cisda.2015.7208644" @default.
- W1566884194 hasPublicationYear "2015" @default.
- W1566884194 type Work @default.
- W1566884194 sameAs 1566884194 @default.
- W1566884194 citedByCount "11" @default.
- W1566884194 countsByYear W15668841942018 @default.
- W1566884194 countsByYear W15668841942019 @default.
- W1566884194 countsByYear W15668841942020 @default.
- W1566884194 countsByYear W15668841942021 @default.
- W1566884194 countsByYear W15668841942023 @default.
- W1566884194 crossrefType "proceedings-article" @default.
- W1566884194 hasAuthorship W1566884194A5032967266 @default.
- W1566884194 hasAuthorship W1566884194A5035349718 @default.
- W1566884194 hasAuthorship W1566884194A5058884064 @default.
- W1566884194 hasAuthorship W1566884194A5079136654 @default.
- W1566884194 hasConcept C111472728 @default.
- W1566884194 hasConcept C111919701 @default.
- W1566884194 hasConcept C114614502 @default.
- W1566884194 hasConcept C121332964 @default.
- W1566884194 hasConcept C124101348 @default.
- W1566884194 hasConcept C124304363 @default.
- W1566884194 hasConcept C126831891 @default.
- W1566884194 hasConcept C12997251 @default.
- W1566884194 hasConcept C138885662 @default.
- W1566884194 hasConcept C154945302 @default.
- W1566884194 hasConcept C18903297 @default.
- W1566884194 hasConcept C199360897 @default.
- W1566884194 hasConcept C23224414 @default.
- W1566884194 hasConcept C26517878 @default.
- W1566884194 hasConcept C26873012 @default.
- W1566884194 hasConcept C2778579508 @default.
- W1566884194 hasConcept C33923547 @default.
- W1566884194 hasConcept C41008148 @default.
- W1566884194 hasConcept C41608201 @default.
- W1566884194 hasConcept C41895202 @default.
- W1566884194 hasConcept C64869954 @default.
- W1566884194 hasConcept C739882 @default.
- W1566884194 hasConcept C74193536 @default.
- W1566884194 hasConcept C75291252 @default.
- W1566884194 hasConcept C79403827 @default.
- W1566884194 hasConcept C86803240 @default.
- W1566884194 hasConceptScore W1566884194C111472728 @default.
- W1566884194 hasConceptScore W1566884194C111919701 @default.
- W1566884194 hasConceptScore W1566884194C114614502 @default.
- W1566884194 hasConceptScore W1566884194C121332964 @default.
- W1566884194 hasConceptScore W1566884194C124101348 @default.
- W1566884194 hasConceptScore W1566884194C124304363 @default.
- W1566884194 hasConceptScore W1566884194C126831891 @default.
- W1566884194 hasConceptScore W1566884194C12997251 @default.
- W1566884194 hasConceptScore W1566884194C138885662 @default.
- W1566884194 hasConceptScore W1566884194C154945302 @default.
- W1566884194 hasConceptScore W1566884194C18903297 @default.
- W1566884194 hasConceptScore W1566884194C199360897 @default.
- W1566884194 hasConceptScore W1566884194C23224414 @default.
- W1566884194 hasConceptScore W1566884194C26517878 @default.
- W1566884194 hasConceptScore W1566884194C26873012 @default.
- W1566884194 hasConceptScore W1566884194C2778579508 @default.
- W1566884194 hasConceptScore W1566884194C33923547 @default.
- W1566884194 hasConceptScore W1566884194C41008148 @default.
- W1566884194 hasConceptScore W1566884194C41608201 @default.
- W1566884194 hasConceptScore W1566884194C41895202 @default.
- W1566884194 hasConceptScore W1566884194C64869954 @default.
- W1566884194 hasConceptScore W1566884194C739882 @default.