Intrusion Detection System Based on Integrated System Calls Graph and Neural Networks

Por favor, use este identificador para citar o enlazar este ítem: http://hdl.handle.net/10045/112150
Información del item - Informació de l'item - Item information
Título: Intrusion Detection System Based on Integrated System Calls Graph and Neural Networks
Autor/es: Mora Gimeno, Francisco José | Mora, Higinio | Volckaert, Bruno | Atrey, Ankita
Grupo/s de investigación o GITE: Arquitecturas Inteligentes Aplicadas (AIA)
Centro, Departamento o Servicio: Universidad de Alicante. Departamento de Tecnología Informática y Computación
Palabras clave: Anomaly detection | Intrusion detection system | Neural networks | System calls graph
Área/s de conocimiento: Arquitectura y Tecnología de Computadores
Fecha de publicación: 5-ene-2021
Editor: IEEE
Cita bibliográfica: IEEE Access. 2021, 9: 9822-9833. https://doi.org/10.1109/ACCESS.2021.3049249
Resumen: Computer security is one of the main challenges of today’s technological infrastructures, whereas intrusion detection systems are one of the most widely used technologies to secure computer systems. The intrusion detection systems use a variety of information sources, one of the most important sources are the applications’ system calls. The intrusion detection systems use many different detection techniques, e.g. system calls sequences, text classification techniques and system calls graphs. However, existing techniques obtain poor results in the detection of complex attack patterns, so it is necessary to improve the detection results. This paper presents an intrusion detection system model that integrates multiple detection techniques into a single system with the goal of modeling the global behavior of the applications. In addition, the paper proposes a new modified system calls graph to integrate and represent the information of the different techniques in a single data structure. The system uses a deep neural network to combine the results of the different detection techniques used in the global model. The result of the study shows the improvement obtained in the detection results with respect to the use of individual techniques, the proposed model achieves higher detection rates and lower false positives. The proposal has been validated onto three datasets with different levels of complexity.
Patrocinador/es: This work was supported by the Conselleria de Innovación, Universidades, Ciencia y Sociedad Digital of the Community of Valencia, Spain, within the Program of Support for Research under Project AICO/2020/206.
URI: http://hdl.handle.net/10045/112150
ISSN: 2169-3536
DOI: 10.1109/ACCESS.2021.3049249
Idioma: eng
Tipo: info:eu-repo/semantics/article
Derechos: This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see https://creativecommons.org/licenses/by/4.0/
Revisión científica: si
Versión del editor: https://doi.org/10.1109/ACCESS.2021.3049249
Aparece en las colecciones:INV - AIA - Artículos de Revistas

Archivos en este ítem:
Archivos en este ítem:
Archivo Descripción TamañoFormato 
ThumbnailMora-Gimeno_etal_2021_IEEEAccess.pdf5,73 MBAdobe PDFAbrir Vista previa


Este ítem está licenciado bajo Licencia Creative Commons Creative Commons