Incremental Bayesian segmentation for intrusion detection
Name
56979320-MIT.pdf
Description
Full printable version
Size
6.41 MB
Format
Adobe PDF
Checksum (MD5)
02aae725e0ca862672600fff131e7ba4
Author(s)
Hastings, Joseph R., 1980-
Advisor(s)
Peter Szolovits.
Date Issued
2004
Publisher
Massachusetts Institute of Technology
Abstract
This thesis describes an attempt to monitor patterns of system calls generated by a Unix host in order to detect potential intrusion attacks. Sequences of system calls generated by privileged processes are analyzed using incremental Bayesian segmentation in order to detect anomalous activity. Theoretical analysis of various aspects of the algorithm and empirical analysis of performance on synthetic data sets are used to tune the algorithm for use as an Intrusion Detection System.
Description
Thesis (M. Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, February 2004.
Includes bibliographical references (leaves 131-133).
Subjects
Electrical Engineering and Computer Science.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.
Persistent DSpace Link