Lightweight Anomaly Detection System with HMM Resource Modeling

Free registration required

Executive Summary

In this paper, a lightweight anomaly detection infrastructure named anomaly detection by resource monitoring is presented for information appliances. The authors call it Ayaka for short. It provides a monitoring function for detecting anomalies, especially attacks which are a symptom of resource abuse, by using the resource patterns of each process. Ayaka takes a completely application black-box approach, based on machine learning methods. It uses the clustering method to quantize the resource usage vector data and then learn the normal patterns with a hidden Markov Model. In the running phase, Ayaka finds anomalies by comparing the application resource usage with the learned model. This reduces the general overhead of the analyzer and makes it possible to monitor the process in real-time.

  • Format: PDF
  • Size: 317.32 KB