Share

Export Citation

APA
MLA
Chicago
Harvard
Vancouver
BIBTEX
RIS
Universitas Hasanuddin
Research output:Contribution to journalArticlepeer-review

Sequence-Based Analysis of Static Probe Instrumentation Data for a VMM-Based Anomaly Detection System

Paundu A.W.

Proceedings 3rd IEEE International Conference on Cyber Security and Cloud Computing Cscloud 2016 and 2nd IEEE International Conference of Scalable and Smart Cloud Ssc 2016

Published: 2016

Abstract

In this work, we propose a framework for a Virtual Machine Monitor (VMM)-based Anomaly Detection System (ADS). This framework uses a sequence-based analysis Hidden Markov Model (HMM) on static probe instrumentation data collected within the VMM. Long observations are split into multiple, uniformed-length, small sequences. The list of likelihood score of sequences in the new observation is compared to a reference list of likelihood scores created from a normal scenario dataset. Statistical distance values from both lists are used to predict the new observation anomaly status. We evaluated the effectiveness of the approach over multiple statistical distance measures and multiple sequence lengths. We also compared our sequence-based analysis results with a frequency-based analysis results that used the One-Class Support Vector Machine (OC-SVM). The results show that the HMM sequence-based analysis can distinguish normal datasets from anomalous datasets better than the OC-SVM frequency-based analysis.

Access to Document

10.1109/CSCloud.2016.51

Other files and links

Fingerprint

Anomaly detectionSciences
Hidden Markov modelSciences
Support vector machineSciences
Computer scienceSciences
Sequence (biology)Sciences
Instrumentation (computer programming)Sciences
System callSciences
Markov modelSciences
Data miningSciences
Pattern recognition (psychology)Sciences
Markov chainSciences
Artificial intelligenceSciences
Machine learningSciences
GeneticsSciences
Programming languageSciences
Operating systemSciences
BiologySciences