{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/process-monitoring-on-sequences-of-system","title":"Process Monitoring on Sequences of System Call Count Vectors","arxiv_id":"1707.03821","date":"2017-07-12","proceeding":null,"authors":["Michael Dymshits","Ben Myara","David Tolpin"],"abstract":"We introduce a methodology for efficient monitoring of processes running on\nhosts in a corporate network. The methodology is based on collecting streams of\nsystem calls produced by all or selected processes on the hosts, and sending\nthem over the network to a monitoring server, where machine learning algorithms\nare used to identify changes in process behavior due to malicious activity,\nhardware failures, or software errors. The methodology uses a sequence of\nsystem call count vectors as the data format which can handle large and varying\nvolumes of data.\n  Unlike previous approaches, the methodology introduced in this paper is\nsuitable for distributed collection and processing of data in large corporate\nnetworks. We evaluate the methodology both in a laboratory setting on a\nreal-life setup and provide statistics characterizing performance and accuracy\nof the methodology.","url_abs":"http://arxiv.org/abs/1707.03821v1","url_pdf":"http://arxiv.org/pdf/1707.03821v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"process-monitoring-on-sequences-of-system","repo_url":"https://github.com/michael135/count-vector-paper-experiments","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}