Borowski, Michal and Saha, Sangeet and Zhai, Xiaojun and McDonald-Maier, Klaus (2023) Benchmark Tool for Detecting Anomalous Program Behaviour on Embedded Devices. In: 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 2022-12-09 - 2022-12-11, Wuhan, China.
Borowski, Michal and Saha, Sangeet and Zhai, Xiaojun and McDonald-Maier, Klaus (2023) Benchmark Tool for Detecting Anomalous Program Behaviour on Embedded Devices. In: 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 2022-12-09 - 2022-12-11, Wuhan, China.
Borowski, Michal and Saha, Sangeet and Zhai, Xiaojun and McDonald-Maier, Klaus (2023) Benchmark Tool for Detecting Anomalous Program Behaviour on Embedded Devices. In: 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 2022-12-09 - 2022-12-11, Wuhan, China.
Abstract
This paper presents an open-source benchmark tool for anomaly detection in program behaviour, using program counter (PC) and instruction type information. It is introducing anomalies in artificial way, allowing for fine-grained evaluation with adjustable sliding window sizes and preprocessing configuration. The usage of the benchmark, including demonstrated data collection, does not require any additional hardware other than a standard computer. The benchmark uses the output of llvm-objdump program to focus on non-library code which allows for rapid evaluation of various detection methods with different configurations. The proposed tool extracts features derived from processor’s PC and instruction type information and then utilizes the features to identify abnormal behavior using 4 different anomaly detection algorithms. New detection methods can be easily incorporated into the benchmark, which provides a solid foundation for evaluating novel, previously unseen methods against methods we selected for our experiment.
Item Type: | Conference or Workshop Item (Paper) |
---|---|
Additional Information: | Published proceedings: _not provided_ |
Uncontrolled Keywords: | anomaly detection; machine learning; benchmark; program counter |
Divisions: | Faculty of Science and Health Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
Depositing User: | Unnamed user with email elements@essex.ac.uk |
Date Deposited: | 12 Jan 2024 11:56 |
Last Modified: | 01 Nov 2024 22:13 |
URI: | http://repository.essex.ac.uk/id/eprint/33558 |
Available files
Filename: Benchmark_tool___IEEE_Conference_Template.pdf
Licence: Creative Commons: Attribution 4.0