2011 IEEE International Workshop on Measurements and Networking Proceedings (M&N) 2011
DOI: 10.1109/iwmn.2011.6088494
|View full text |Cite
|
Sign up to set email alerts
|

Towards identifying OS-level anomalies to detect application software failures

Abstract: The next generation of critical systems, namely complex Critical Infrastructures (LCCIs), require efficient runtime management, reconfiguration strategies, and the ability to take decisions on the basis of current and past behavior of the system. Anomaly-based detection, leveraging information gathered at Operating System (OS) level (e.g., number of system call errors, signals, and holding semaphores in the time unit), seems to be a promising approach to reveal online application faults. Recently an experiment… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
6
0

Year Published

2013
2013
2016
2016

Publication Types

Select...
2
2
1

Relationship

3
2

Authors

Journals

citations
Cited by 5 publications
(6 citation statements)
references
References 7 publications
0
6
0
Order By: Relevance
“…Recent studies [8] and our earlier works [9], [10] show that revealing anomalies at operating system (OS) level is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) have poor performance or have limited applicability. 1 The driving idea is to shift the observation perspective to the OS, monitoring its behavior and interactions with the applications.…”
Section: Introductionmentioning
confidence: 99%
“…Recent studies [8] and our earlier works [9], [10] show that revealing anomalies at operating system (OS) level is a promising approach when traditional detection mechanisms (e.g., based on event logs, probes and heartbeats) have poor performance or have limited applicability. 1 The driving idea is to shift the observation perspective to the OS, monitoring its behavior and interactions with the applications.…”
Section: Introductionmentioning
confidence: 99%
“…This dataset is the result of the experimental campaign performed in [2], where the authors implemented an instrumentation infrastructures able to collect OS-level indicators, both for Linux and Windows environments. The testing activity was performed analyzing a large amount of data monitored in a real and complex case application, namely the SWIM-BOX® [2], a prototype to support global interoperability for the novel Air Traffic Management (ATM) systems. SWIM-BOX is deployed on Windows and Linux platforms.…”
Section: The Experimental Datasetmentioning
confidence: 99%
“…The model is then used to detect performance anomalies, namely those changes in CPU usage not clearly justified by the actual workload. In [2] the authors propose a configurable detection framework to reveal anomalies in the OS behavior, related to system misbehaviors (software faults injected at the application level). For each monitored OS indicator, the framework computes lower and upper adaptive thresholds in order to take into account the dynamic behavior of the system.…”
Section: Introductionmentioning
confidence: 99%
See 2 more Smart Citations