Description of Computer System State for Intrusion Detection

침입 탐지를 위한 컴퓨터 시스템 상태 기술

  • 곽미라 (이화여자대학교 컴퓨터학과) ;
  • 조동섭 (이화여자대학교 컴퓨터학과)
  • Published : 2006.04.29

Abstract

We designed an intelligent intrusion detection scheme that works based on target system's operational states and doesn't depend on humans' analysis. As a prior work, we presents a scheme to describe computer system's operational states. For this, Hidden Markov Model is used. As input to modeling, huge amount of system audit trail including data on events occurred in target system connected to network and target system's resource usage monitoring data is used. We can predict system's future state based on current events' sequence using developed model and determine whether it would be in daniel or not.

Keywords