WANG Xiu-li, WANG Yong-ji. Masquerader Detection Based on Command Closeness Model[J]. Acta Electronica Sinica, 2014, 42(6): 1225-1229.
DOI:
WANG Xiu-li, WANG Yong-ji. Masquerader Detection Based on Command Closeness Model[J]. Acta Electronica Sinica, 2014, 42(6): 1225-1229. DOI: 10.3969/j.issn.0372-2112.2014.06.029.
Masquerader Detection Based on Command Closeness Model
According to the history of command sequence in Unix system
an approach to masquerader detection based on the closeness model of command was proposed.The behavior patterns of user were extracted from the view of command combinations.Those commands combined frequently by users showed close relationship
and other commands exhibited loose relationship.Command closeness matrix was generated by the sliding window from the sequence of commands.If the command block to be detected exhibited a low closeness for the user
it was judged as abnormal.Experimental results show that a simple calculation
an accurate detection
and a high level of real-time can be achieved by using the proposed approach.