Article

Article title MODEL OF THE ANOMALOUS BEHAVIOR OF THE SYSTEM BASED ON PROBABILISTIC SUFFIX TREES
Authors G.E. Abramov
Section SECTION II. SECURITY OF INFORMATION SYSTEMS AND NETWORKS
Month, Year 11, 2009 @en
Index UDC 681.324
DOI
Abstract Described the method of probabilistic suffix trees for detecting anomalous behavior of programs. Use "fingerprint" of the normal behavior of applications in order to further detect anomalous behavior as something deviating from the model. As a basic model uses a probabilistic suffix trees.

Download PDF

Keywords Probabilistic suffix tree; PST; detection of abnormal behavior.
References 1. D. Ron, Y. Singer, and N. Tishby. The power of amnesia: Learning probabilisitc automata with variable memory length. Machine Learning, 25:117–142, 1996.
2. M. Schonlau, W. DuMouchel, W. Ju, A. Karr, M. Theus, and Y. Vardi. Computer
intrusion: Detecting masquerades. Statistical Science, 16:1–17, 2001.

Comments are closed.