Introduction - If you have any usage issues, please Google them yourself
In the existing single-layer Markov chain model for anomaly detection based on a new two-tier model. Will have a larger difference in the nature of the two processes, different requests and requests within the same system call sequence, sub- for a two-tier, respectively, in different Markov chain to deal with it. a two-tier structure can be more accurately portray the process of protection services by the dynamic behavior, which can greatly improve the identification of abnormal rate and reduce false alarm rate.