Description: In the existing single-layer Markov chain model for anomaly detection based on a new two-tier model. Will have a larger difference in the nature of the two processes, different requests and requests within the same system call sequence, sub- for a two-tier, respectively, in different Markov chain to deal with it. a two-tier structure can be more accurately portray the process of protection services by the dynamic behavior, which can greatly improve the identification of abnormal rate and reduce false alarm rate.
File list (Check if you may need any files):