Skip to Main Content
System call trace is one of the behavior characteristics of system process. Each system call of the trace depends on several previous system calls. Using Markov model to capture such probabilistic characteristic of the system call is time consuming. Thus, we use Probabilistic Suffix Tree to extract this feature. PST is trained with the normal system call traces. We define a new measure of abnormal system call trace based on the PST to detect abnormal processes. Experiments show that this measurement can well distinguish between normal and abnormal process.