Netinfo Security ›› 2016, Vol. 16 ›› Issue (9): 108-112.doi: 10.3969/j.issn.1671-1122.2016.09.022

• Orginal Article • Previous Articles     Next Articles

Program Behavior Anomaly Detection Method Based on Improved HMM

Xin WU(), Yuesong YAN, Xiaoran LIU   

  1. Naval Command College, Nanjing Jiangsu 211800, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

Abstract:

Anomaly detection of program behavior is an important part of network anomaly detection. In traditional HMM, the probability of transition and the probability of the observed value is only related to the previous state, which leads to high false alarm rate and low detection rate. In this paper an improved 2HMM detection method is proposed, which is based on local regularity of the system calls. And in order to reduce the training time, the model uses a more simple parameter estimation algorithm. Finally, through the experiment, compared with the traditional HMM and traditional 2HMM,the superiority of the model is proved.

Key words: program behavior, anomaly detection, HMM

CLC Number: