CRMay 16, 2018

A Survey of Intrusion Detection Systems Leveraging Host Data

arXiv:1805.06070v29 citations
Originality Synthesis-oriented
AI Analysis

This is an incremental survey paper that synthesizes existing research on host-based intrusion detection systems for cybersecurity practitioners and researchers.

This survey organizes and analyzes intrusion detection systems that use host-based data sources to detect enterprise network attacks, covering system logs, audit data, Windows Registry, file systems, and program analysis, while including sections on publicly available datasets and algorithmic developments.

This survey focuses on intrusion detection systems (IDS) that leverage host-based data sources for detecting attacks on enterprise network. The host-based IDS (HIDS) literature is organized by the input data source, presenting targeted sub-surveys of HIDS research leveraging system logs, audit data, Windows Registry, file systems, and program analysis. While system calls are generally included in audit data, several publicly available system call datasets have spawned a flurry of IDS research on this topic, which merits a separate section. Similarly, a section surveying algorithmic developments that are applicable to HIDS but tested on network data sets is included, as this is a large and growing area of applicable literature. To accommodate current researchers, a supplementary section giving descriptions of publicly available datasets is included, outlining their characteristics and shortcomings when used for IDS evaluation. Related surveys are organized and described. All sections are accompanied by tables concisely organizing the literature and datasets discussed. Finally, challenges, trends, and broader observations are throughout the survey and in the conclusion along with future directions of IDS research.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes