p.2195
p.2199
p.2203
p.2208
p.2212
p.2217
p.2221
p.2225
p.2229
Abnormal File Access Behavior Detection Based on FPD: An Unsupervised Approach
Abstract:
Information security is a great challenge for organizations in our modern information world. Existing security facilities like Firewalls, Intrusion Detection Systems and Antivirus are not enough to guarantee the security of information. File is an important carrier of information, which is the intent of quite a number of attackers. In this paper, we extend the FPD-based approach for detecting abnormal file access behaviors. We propose 3 approaches to calculate FPD values in the case of lacking training data, and we apply a k-means based unsupervised approach to distinguish between normal processes and abnormal ones. Experiment demonstrate that our unsupervised approach is still effective compared to the supervised case with training data.
Info:
Periodical:
Pages:
2212-2216
Citation:
Online since:
January 2015
Authors:
Price:
Сopyright:
© 2015 Trans Tech Publications Ltd. All Rights Reserved
Share:
Citation: