{"id":"https://openalex.org/W2118372007","doi":"https://doi.org/10.1109/tdsc.2008.69","title":"Detecting Intrusions through System Call Sequence and Argument Analysis","display_name":"Detecting Intrusions through System Call Sequence and Argument Analysis","publication_year":2008,"publication_date":"2008-12-03","ids":{"openalex":"https://openalex.org/W2118372007","doi":"https://doi.org/10.1109/tdsc.2008.69","mag":"2118372007"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2008.69","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2008.69","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://hdl.handle.net/11311/578281","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055678575","display_name":"Federico Maggi","orcid":"https://orcid.org/0000-0003-1073-8036"},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Federico Maggi","raw_affiliation_strings":["Dipartimento di Elettronica e Informazione, Politecnico di Milano, Milan, Italy","Dipt. di Elettron. e Inf., Politec. di Milano, Milano, Italy"],"affiliations":[{"raw_affiliation_string":"Dipartimento di Elettronica e Informazione, Politecnico di Milano, Milan, Italy","institution_ids":["https://openalex.org/I93860229"]},{"raw_affiliation_string":"Dipt. di Elettron. e Inf., Politec. di Milano, Milano, Italy","institution_ids":["https://openalex.org/I93860229"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003932703","display_name":"Matteo Matteucci","orcid":"https://orcid.org/0000-0002-8306-6739"},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Matteo Matteucci","raw_affiliation_strings":["Dipartimento di Elettronica e Informazione, Politecnico di Milano, Milan, Italy","Dipt. di Elettron. e Inf., Politec. di Milano, Milano, Italy"],"affiliations":[{"raw_affiliation_string":"Dipartimento di Elettronica e Informazione, Politecnico di Milano, Milan, Italy","institution_ids":["https://openalex.org/I93860229"]},{"raw_affiliation_string":"Dipt. di Elettron. e Inf., Politec. di Milano, Milano, Italy","institution_ids":["https://openalex.org/I93860229"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046604572","display_name":"Stefano Zanero","orcid":"https://orcid.org/0000-0003-4710-5283"},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Stefano Zanero","raw_affiliation_strings":["Dipartimento di Elettronica e Informazione, Politecnico di Milano, Milan, Italy","Dipt. di Elettron. e Inf., Politec. di Milano, Milano, Italy"],"affiliations":[{"raw_affiliation_string":"Dipartimento di Elettronica e Informazione, Politecnico di Milano, Milan, Italy","institution_ids":["https://openalex.org/I93860229"]},{"raw_affiliation_string":"Dipt. di Elettron. e Inf., Politec. di Milano, Milano, Italy","institution_ids":["https://openalex.org/I93860229"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5055678575"],"corresponding_institution_ids":["https://openalex.org/I93860229"],"apc_list":null,"apc_paid":null,"fwci":4.3994,"has_fulltext":false,"cited_by_count":142,"citation_normalized_percentile":{"value":0.94790444,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":93,"max":100},"biblio":{"volume":"7","issue":"4","first_page":"381","last_page":"395"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.9362390041351318},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8219571113586426},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7350270748138428},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.6674203872680664},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.5541764497756958},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5328928232192993},{"id":"https://openalex.org/keywords/sequence","display_name":"Sequence (biology)","score":0.5184923410415649},{"id":"https://openalex.org/keywords/hidden-markov-model","display_name":"Hidden Markov model","score":0.5061387419700623},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.49386221170425415},{"id":"https://openalex.org/keywords/markov-process","display_name":"Markov process","score":0.4621489942073822},{"id":"https://openalex.org/keywords/argument","display_name":"Argument (complex analysis)","score":0.4223727285861969},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4191034138202667},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.379899263381958},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.34051647782325745}],"concepts":[{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.9362390041351318},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8219571113586426},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7350270748138428},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.6674203872680664},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5541764497756958},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5328928232192993},{"id":"https://openalex.org/C2778112365","wikidata":"https://www.wikidata.org/wiki/Q3511065","display_name":"Sequence (biology)","level":2,"score":0.5184923410415649},{"id":"https://openalex.org/C23224414","wikidata":"https://www.wikidata.org/wiki/Q176769","display_name":"Hidden Markov model","level":2,"score":0.5061387419700623},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.49386221170425415},{"id":"https://openalex.org/C159886148","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov process","level":2,"score":0.4621489942073822},{"id":"https://openalex.org/C98184364","wikidata":"https://www.wikidata.org/wiki/Q1780131","display_name":"Argument (complex analysis)","level":2,"score":0.4223727285861969},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4191034138202667},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.379899263381958},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34051647782325745},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0},{"id":"https://openalex.org/C54355233","wikidata":"https://www.wikidata.org/wiki/Q7162","display_name":"Genetics","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tdsc.2008.69","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2008.69","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},{"id":"pmh:oai:re.public.polimi.it:11311/578281","is_oa":true,"landing_page_url":"http://hdl.handle.net/11311/578281","pdf_url":null,"source":{"id":"https://openalex.org/S4306400312","display_name":"Virtual Community of Pathological Anatomy (University of Castilla La Mancha)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79189158","host_organization_name":"University of Castilla-La Mancha","host_organization_lineage":["https://openalex.org/I79189158"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"}],"best_oa_location":{"id":"pmh:oai:re.public.polimi.it:11311/578281","is_oa":true,"landing_page_url":"http://hdl.handle.net/11311/578281","pdf_url":null,"source":{"id":"https://openalex.org/S4306400312","display_name":"Virtual Community of Pathological Anatomy (University of Castilla La Mancha)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79189158","host_organization_name":"University of Castilla-La Mancha","host_organization_lineage":["https://openalex.org/I79189158"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"},"sustainable_development_goals":[{"score":0.699999988079071,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W575113220","https://openalex.org/W1497959280","https://openalex.org/W1575798196","https://openalex.org/W1583975142","https://openalex.org/W1587265799","https://openalex.org/W1591480890","https://openalex.org/W1670263352","https://openalex.org/W1832277845","https://openalex.org/W1863862444","https://openalex.org/W1941427975","https://openalex.org/W1963563131","https://openalex.org/W1984350393","https://openalex.org/W1988918299","https://openalex.org/W1999427165","https://openalex.org/W2002380285","https://openalex.org/W2014366246","https://openalex.org/W2053727222","https://openalex.org/W2086469601","https://openalex.org/W2093488494","https://openalex.org/W2101146371","https://openalex.org/W2102941975","https://openalex.org/W2106649514","https://openalex.org/W2117316063","https://openalex.org/W2118528519","https://openalex.org/W2123886726","https://openalex.org/W2125109784","https://openalex.org/W2125838338","https://openalex.org/W2129624205","https://openalex.org/W2129860818","https://openalex.org/W2131970275","https://openalex.org/W2135143063","https://openalex.org/W2149086123","https://openalex.org/W2150847526","https://openalex.org/W2160892968","https://openalex.org/W2162995740","https://openalex.org/W2169959739","https://openalex.org/W2170973665","https://openalex.org/W2338717024","https://openalex.org/W2519765358","https://openalex.org/W2598912124","https://openalex.org/W2615155959","https://openalex.org/W3004355593","https://openalex.org/W3121147667","https://openalex.org/W3136767761","https://openalex.org/W3214373139","https://openalex.org/W4236777759","https://openalex.org/W6635224074","https://openalex.org/W6677163426","https://openalex.org/W6678648185","https://openalex.org/W6684391152","https://openalex.org/W6774024915","https://openalex.org/W6803782233"],"related_works":["https://openalex.org/W1996865198","https://openalex.org/W11100131","https://openalex.org/W2385758958","https://openalex.org/W2183313954","https://openalex.org/W1969635302","https://openalex.org/W1805274772","https://openalex.org/W2532369412","https://openalex.org/W2376046849","https://openalex.org/W3146948916","https://openalex.org/W1973375107"],"abstract_inverted_index":{"We":[0,15,30],"describe":[1,32],"an":[2],"unsupervised":[3],"host-based":[4],"intrusion":[5],"detection":[6,21],"system":[7,10,43,54,74],"based":[8],"on":[9],"call":[11,44],"arguments":[12,45,51],"and":[13,46,69,86,109],"sequences.":[14],"define":[16],"a":[17,33,53,59,82,103],"set":[18],"of":[19,27,52],"anomaly":[20],"models":[22,41],"for":[23],"the":[24,28,96,115],"individual":[25,125],"parameters":[26],"call.":[29,55],"then":[31],"clustering":[34],"process":[35],"that":[36],"helps":[37],"to":[38,42,65,91,100,110,121],"better":[39],"fit":[40],"creates":[47],"interrelations":[48],"among":[49],"different":[50],"Finally,":[56],"we":[57],"add":[58],"behavioral":[60],"Markov":[61],"model":[62],"in":[63],"order":[64],"capture":[66],"time":[67],"correlations":[68],"abnormal":[70],"behaviors.":[71],"The":[72],"whole":[73],"needs":[75],"no":[76],"prior":[77],"knowledge":[78],"input;":[79],"it":[80,87],"has":[81],"good":[83],"signal-to-noise":[84],"ratio,":[85],"is":[88],"also":[89],"able":[90],"correctly":[92],"contextualize":[93],"alarms,":[94],"giving":[95],"user":[97],"more":[98],"information":[99],"understand":[101],"whether":[102],"true":[104],"or":[105],"false":[106],"positive":[107],"happened,":[108],"detect":[111],"global":[112],"variations":[113],"over":[114,124],"entire":[116],"execution":[117],"flow,":[118],"as":[119],"opposed":[120],"punctual":[122],"ones":[123],"instances.":[126]},"counts_by_year":[{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":15},{"year":2019,"cited_by_count":11},{"year":2018,"cited_by_count":11},{"year":2017,"cited_by_count":12},{"year":2016,"cited_by_count":8},{"year":2015,"cited_by_count":18},{"year":2014,"cited_by_count":7},{"year":2013,"cited_by_count":12},{"year":2012,"cited_by_count":13}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
