Masquerade detection based upon GUI user profiling in Linux systems

dc.contributor.author Bhukya, Wilson Naik
dc.contributor.author Kommuru, Suneel Kumar
dc.contributor.author Negi, Atul
dc.date.accessioned 2022-03-27T05:51:50Z
dc.date.available 2022-03-27T05:51:50Z
dc.date.issued 2007-01-01
dc.description.abstract Masquerading or impersonation attack refers to the act of gaining access to confidential data or greater access privileges, while pretending to be legitimate users. Detection of masquerade attacks is of great importance and is a non-trivial task of system security. Detection of these attacks is done by monitoring significant changes in user's behavior based on his/her computer usage. Traditional detection mechanisms are based on command line system events collected using log files. In a GUI based system, most of the user activities are performed using either mouse movements and clicks or a combination of mouse movements and keystrokes. The command line data cannot capture the complete GUI event behavior of the users hence it is insufficient to detect attacks in GUI based systems. Presently, there is no frame work available to capture the GUI based user behavior in Linux systems. We are proposing a novel approach to capture the GUI based user behavior for Linux systems using our event logging tool. Our experimentation results shows that, the GUI based user behavior can be efficiently used for masquerade attack detection to achieve high detection rates with less false positives. We have applied One-class SVM on the collected data, which requires only training the user's own legitimate sessions to build up the user's profile. Our results on GUI data using One-class SVM gives higher detection rates with less false positives compared to a Two-class SVM approach. © Springer-Verlag Berlin Heidelberg 2007.
dc.identifier.citation Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). v.4846 LNCS
dc.identifier.issn 03029743
dc.identifier.uri 10.1007/978-3-540-76929-3_21
dc.identifier.uri http://link.springer.com/10.1007/978-3-540-76929-3_21
dc.identifier.uri https://dspace.uohyd.ac.in/handle/1/8449
dc.subject Anomaly detection
dc.subject GUI based profiling
dc.subject Intrusion detection
dc.subject KDE
dc.subject Linux profiling
dc.subject Masquerade detection
dc.subject Mouse events
dc.subject One-class SVM
dc.title Masquerade detection based upon GUI user profiling in Linux systems
dc.type Book Series. Conference Paper
dspace.entity.type
Files
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description: