Abstract:
Host-based Intrusion Detection System (IDS) are based on comparing the system call trace of a process against a set of k-grams. A simple extension to self-based IDS incorporates system call arguments and process privileges either to reduce or make Mimicry attacks more difficult. To avoid increasing the false positives supplied, specifications has to be used to abstract the system call arguments and process credentials. The specification takes into account what objects in the system that can be sensitive to potential attacks.
Reference this Research Paper (copy & paste below code):
M.Lakshmi Deepthi, Dr.N.Kumarathan (2018); Reduction of Mimicry Attacks on Host -Based Intrusion Detection System using Argument Abstraction;
Int J Sci Res Publ 2(11) (ISSN: 2250-3153). http://www.ijsrp.org/research-paper-1112.php?rp=P11425