Linux Symposium, July 13th - 17th, 2009, Montreal, Canada
Centre Mont-Royal
Montreal, Canada
July 13-17, 2009

Register / Login

CFP
Paper Guide

Schedule

Keynotes
Summits
Presentations
Tutorials
BOFS

Venue
Travel & Hotel
Costs & Savings

FAQ

Media
Archives
Contact

Home



Anomaly-based intrusion detection on Linux with pH

Mario Van Velzen (mario.vanvelzen@gmail.com)

Anomaly-based intrusion detection systems can use rules or models from learned behaviour to determine if misuse is occurring. Rules can be difficult to write and maintain. Models learned from actual usage allow the system to better determine normal and abnormal behaviour. For computer programs, information about systems calls has been shown to be useful in modeling the operation of programs for security purposes.

We present pH, a Linux implementation of such a system, which builds models from system calls, uses these models to identify abnormal behaviour, and delays or aborts abnormal system calls. We will focus on implementation, performance, and mitigation of false positives.



Major Sponsors
Minor Sponsors
Wireless Networking

register | call for papers

Copyright © 2009 Linux Symposium Inc. All rights reserved.
Linux is a registered trademark of Linus Torvalds.