Process Flow Features as a Host-Based Event Knowledge Representation

Abstract

The detection of malware is of great importance but even non-malicious software can be used for malicious purposes. Monitoring processes and their associated information can characterize normal behavior and help identify malicious processes or malicious use of normal process by measuring deviations from the learned baseline. This exploratory research describes a novel host feature generation process that calculates statistics of an executing process during a window of time called a process flow. Process flows are calculated from key process data structures extracted from computer memory using virtual machine introspection. Each flow cluster generated using k-means of the flow features represents a behavior where the members of the cluster all exhibit similar behavior. Testing explores associations between behavior and process flows that in the future may be useful for detecting unauthorized behavior or behavioral trends on a host. Analysis of two data collections demonstrate that this novel way of thinking of process behavior as process flows can produce baseline models in the form of clusters that do represent specific behaviors.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Jun 14, 2012
Accession Number
ADA563042

Entities

People

  • Benhur E. Pacer Jr.

Organizations

  • Air Force Institute of Technology

Tags

Communities of Interest

  • Autonomy
  • Cyber
  • Energy and Power Technologies

DTIC Thesaurus Topics

  • Air Force
  • Anomaly Detection
  • Change Detection
  • Computational Science
  • Computer Programming
  • Computers
  • Cybersecurity
  • Data Mining
  • Detectors
  • Information Science
  • Information Systems
  • Intrusion Detectors
  • Machine Learning
  • Neural Networks
  • Operating Systems
  • Social Media
  • Web Browsers

Fields of Study

  • Computer science

Readers

  • Computational Modeling and Simulation
  • Cybersecurity.
  • Team-Based Human-Centered Cognitive Task Decision Making and Information Performance.

Technology Areas

  • Cyber