Przemysław Maciołek, Paweł Król, Jarosław Koźlak


We present an application of probabilistic approach to the anomaly detection (PAD). Byanalyzing selected system calls (and their arguments), the chosen applications are monitoredin the Linux environment. This allows us to estimate “(ab)normality” of their behavior (bycomparison to previously collected profiles). We’ve attached results of threat detection ina typical computer environment.


anomaly detection; IDS; system calls; Linux

Full Text:



