A new method for data collection and anomaly detection of hosts is proposed to focus on the problems that the methods based on signature matching cannot detect unknown anomaly and data collection agents occupy too many host resources. Intelligent mobile agents are employed to perform data collection so that the number of collection agents is greatly reduced. In order to achieve the goal of online anomaly detection
the principal component analysis method is employed to reduce the dimension of the data
and the clustering method is used to mine the abnormal events. The host anomaly detection method based on continuous time windows is adopted to eliminate the influence of random outliers. Experimental results show that the proposed method has lower computational complexity and higher detection accuracy
and for same number of records the time complexity is reduced by more than 50% and the detection accuracy is above 95%
compared with conventional method. It is concluded that the method is suitable for real-time detection of host anomaly.
NI Guiqiang, LI Jiazhen, PAN Zhisong, et al. Verification based on keystroke biologic characteristics using support vector data description [J]. Pattern Recognition and Artificial Intelligence, 2008, 21(5): 704-708.
CAI Zhongmin, SHEN Chao, GUAN Xiaohong. Mitigating behavioral variability for mouse dynamics: a dimensionality reduction method [J]. IEEE Transactions on Human-Machine Systems, 2014, 44(2): 244-255.
PENNINGTON A, STUNK J, GRIFFIN J, et al. Storage based intrusion detection: watching storage activity for suspicious behavior [C]∥Proceedings of the 12th USENIX Security Symposium. New York, USA: ACM, 2003: 137-151.
FORREST S, HOFMEYR A, SOMAYAJI A, et al. A sense of self for UNIX processes [C]∥Proceedings of the 1996 IEEE Symposium on Security and Privacy. Piscataway, NJ, USA: IEEE Communication Society, 1996: 120-128.
LI Han, BAO Lihui. Research and implementation of an anomaly intrusion detection system model based on cluster analysis [J]. Computer Applications and Software, 2006, 23(10): 126-127.
HAN Sangjun, CHO Sungbae. Rule-based integration of multiple measure-models for effective intrusion detection systems [C]∥Proceedings of the 2003 IEEE International Conference on Man and Cybernetics. Piscataway, NJ, USA: IEEE System, Man and Cybernetics Society, 2003: 120-125.
TAO Jing, MA Xiaobo, ZHAO Juan, et al. A method for host abnormal detection based on resource availability [J]. Journal of University of Electronic Science and Technology of China, 2007, 36(S3): 1449-1452.
DALMEIJER M, HAMMER D, AERTS A. Mobile software agents [J]. Computers in Industry, 2000, 41(3): 251-260.
IBM. IBM aglets software development kit-home page [EB/OL].(2003-06-23)[2014-05-10]. http: ∥web. media.mit.edu/~stefanm/ibm/AgletsHome Page/index_new4.html.
赵蔷. 主成分分析方法综述 [J]. 软件工程, 2016, 6(19): 1-3.
ZHAO Qiang. A review of principal component analysis [J]. Software Engineering, 2016, 6(19): 1-3.
CAMPELLO R, MOULAVI D, SANDER J. Density based clustering based on hierarchical density estimates [C]∥Proceedings of the 17th Pacific-Asia Conference on Knowledge Discovery in Databases. Berlin, Germany: Springer, 2013: 160-172.