Pith. sign in

REVIEW

Learning Execution Contexts from System Call Distributions for Intrusion Detection in Embedded Systems

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1501.05963 v2 pith:FQAGRZKE submitted 2015-01-23 cs.CR

classification cs.CR
keywords embeddedexecutionexecutionsanomalouscallcontextsdetectionintrusion
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Existing techniques used for intrusion detection do not fully utilize the intrinsic properties of embedded systems. In this paper, we propose a lightweight method for detecting anomalous executions using a distribution of system call frequencies. We use a cluster analysis to learn the legitimate execution contexts of embedded applications and then monitor them at run-time to capture abnormal executions. We also present an architectural framework with minor processor modifications to aid in this process. Our prototype shows that the proposed method can effectively detect anomalous executions without relying on sophisticated analyses or affecting the critical execution paths.

Discussion (0). Sign in to comment.

Pith tools