Ontology type: schema:Chapter Open Access: True
2006
AUTHORSDebin Gao , Michael K. Reiter , Dawn Song
ABSTRACTWe introduce a notion, behavioral distance, for evaluating the extent to which processes—potentially running different programs and executing on different platforms—behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead. More... »
PAGES63-81
Recent Advances in Intrusion Detection
ISBN
978-3-540-31778-4
978-3-540-31779-1
http://scigraph.springernature.com/pub.10.1007/11663812_4
DOIhttp://dx.doi.org/10.1007/11663812_4
DIMENSIONShttps://app.dimensions.ai/details/publication/pub.1051888941
JSON-LD is the canonical representation for SciGraph data.
TIP: You can open this SciGraph record using an external JSON-LD service: JSON-LD Playground Google SDTT
[
{
"@context": "https://springernature.github.io/scigraph/jsonld/sgcontext.json",
"about": [
{
"id": "http://purl.org/au-research/vocabulary/anzsrc-for/2008/08",
"inDefinedTermSet": "http://purl.org/au-research/vocabulary/anzsrc-for/2008/",
"name": "Information and Computing Sciences",
"type": "DefinedTerm"
},
{
"id": "http://purl.org/au-research/vocabulary/anzsrc-for/2008/0806",
"inDefinedTermSet": "http://purl.org/au-research/vocabulary/anzsrc-for/2008/",
"name": "Information Systems",
"type": "DefinedTerm"
}
],
"author": [
{
"affiliation": {
"alternateName": "Electrical & Computer Engineering Department, Carnegie Mellon University, Pittsburgh, Pennsylvania, USA",
"id": "http://www.grid.ac/institutes/grid.147455.6",
"name": [
"Electrical & Computer Engineering Department, Carnegie Mellon University, Pittsburgh, Pennsylvania, USA"
],
"type": "Organization"
},
"familyName": "Gao",
"givenName": "Debin",
"id": "sg:person.013015522271.54",
"sameAs": [
"https://app.dimensions.ai/discover/publication?and_facet_researcher=ur.013015522271.54"
],
"type": "Person"
},
{
"affiliation": {
"alternateName": "Electrical & Computer Engineering Department, Computer Science Department, and CyLab, Carnegie Mellon University, Pittsburgh, Pennsylvania, USA",
"id": "http://www.grid.ac/institutes/grid.147455.6",
"name": [
"Electrical & Computer Engineering Department, Computer Science Department, and CyLab, Carnegie Mellon University, Pittsburgh, Pennsylvania, USA"
],
"type": "Organization"
},
"familyName": "Reiter",
"givenName": "Michael K.",
"id": "sg:person.01265200500.82",
"sameAs": [
"https://app.dimensions.ai/discover/publication?and_facet_researcher=ur.01265200500.82"
],
"type": "Person"
},
{
"affiliation": {
"alternateName": "Electrical & Computer Engineering Department, Computer Science Department, and CyLab, Carnegie Mellon University, Pittsburgh, Pennsylvania, USA",
"id": "http://www.grid.ac/institutes/grid.147455.6",
"name": [
"Electrical & Computer Engineering Department, Computer Science Department, and CyLab, Carnegie Mellon University, Pittsburgh, Pennsylvania, USA"
],
"type": "Organization"
},
"familyName": "Song",
"givenName": "Dawn",
"id": "sg:person.01143152610.86",
"sameAs": [
"https://app.dimensions.ai/discover/publication?and_facet_researcher=ur.01143152610.86"
],
"type": "Person"
}
],
"datePublished": "2006",
"datePublishedReg": "2006-01-01",
"description": "We introduce a notion, behavioral distance, for evaluating the extent to which processes\u2014potentially running different programs and executing on different platforms\u2014behave similarly in response to a common input. We explore behavioral distance as a means to detect an attack on one process that causes its behavior to deviate from that of another. We propose a measure of behavioral distance and a realization of this measure using the system calls emitted by processes. Through an empirical evaluation of this measure using three web servers on two different platforms (Linux and Windows), we demonstrate that this approach holds promise for better intrusion detection with moderate overhead.",
"editor": [
{
"familyName": "Valdes",
"givenName": "Alfonso",
"type": "Person"
},
{
"familyName": "Zamboni",
"givenName": "Diego",
"type": "Person"
}
],
"genre": "chapter",
"id": "sg:pub.10.1007/11663812_4",
"inLanguage": "en",
"isAccessibleForFree": true,
"isPartOf": {
"isbn": [
"978-3-540-31778-4",
"978-3-540-31779-1"
],
"name": "Recent Advances in Intrusion Detection",
"type": "Book"
},
"keywords": [
"intrusion detection",
"better intrusion detection",
"behavioral distance",
"system calls",
"web server",
"moderate overhead",
"different platforms",
"empirical evaluation",
"server",
"overhead",
"different programs",
"common input",
"attacks",
"platform",
"detection",
"input",
"distance",
"process",
"measures",
"realization",
"calls",
"notion",
"response",
"evaluation",
"program",
"means",
"promise",
"extent",
"behavior",
"approach"
],
"name": "Behavioral Distance for Intrusion Detection",
"pagination": "63-81",
"productId": [
{
"name": "dimensions_id",
"type": "PropertyValue",
"value": [
"pub.1051888941"
]
},
{
"name": "doi",
"type": "PropertyValue",
"value": [
"10.1007/11663812_4"
]
}
],
"publisher": {
"name": "Springer Nature",
"type": "Organisation"
},
"sameAs": [
"https://doi.org/10.1007/11663812_4",
"https://app.dimensions.ai/details/publication/pub.1051888941"
],
"sdDataset": "chapters",
"sdDatePublished": "2022-05-10T10:55",
"sdLicense": "https://scigraph.springernature.com/explorer/license/",
"sdPublisher": {
"name": "Springer Nature - SN SciGraph project",
"type": "Organization"
},
"sdSource": "s3://com-springernature-scigraph/baseset/20220509/entities/gbq_results/chapter/chapter_64.jsonl",
"type": "Chapter",
"url": "https://doi.org/10.1007/11663812_4"
}
]
Download the RDF metadata as: json-ld nt turtle xml License info
JSON-LD is a popular format for linked data which is fully compatible with JSON.
curl -H 'Accept: application/ld+json' 'https://scigraph.springernature.com/pub.10.1007/11663812_4'
N-Triples is a line-based linked data format ideal for batch operations.
curl -H 'Accept: application/n-triples' 'https://scigraph.springernature.com/pub.10.1007/11663812_4'
Turtle is a human-readable linked data format.
curl -H 'Accept: text/turtle' 'https://scigraph.springernature.com/pub.10.1007/11663812_4'
RDF/XML is a standard XML format for linked data.
curl -H 'Accept: application/rdf+xml' 'https://scigraph.springernature.com/pub.10.1007/11663812_4'
This table displays all metadata directly associated to this object as RDF triples.
111 TRIPLES
23 PREDICATES
56 URIs
49 LITERALS
7 BLANK NODES