{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:42:54Z","timestamp":1781109774348,"version":"3.54.1"},"reference-count":24,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010,1,1]]},"abstract":"<p>Application features like port numbers are used by Network-based Intrusion Detection Systems (NIDSs) to detect attacks coming from networks. System calls and the operating system related information are used by Host-based Intrusion Detection Systems (HIDSs) to detect intrusions toward a host. However, the relationship between hardware architecture events and Denial-of-Service (DoS) attacks has not been well revealed. When increasingly sophisticated intrusions emerge, some attacks are able to bypass both the application and the operating system level feature monitors. Therefore, a more effective solution is required to enhance existing HIDSs. In this article, the authors identify the following hardware architecture features: Instruction Count, Cache Miss, Bus Traffic and integrate them into a HIDS framework based on a modern statistical Gradient Boosting Trees model. Through the integration of application, operating system and architecture level features, the proposed HIDS demonstrates a significant improvement of the detection rate in terms of sophisticated DoS intrusions.<\/p>","DOI":"10.4018\/jisp.2010010102","type":"journal-article","created":{"date-parts":[[2010,4,19]],"date-time":"2010-04-19T19:03:06Z","timestamp":1271703786000},"page":"18-31","source":"Crossref","is-referenced-by-count":0,"title":["A Host-Based Intrusion Detection System Using Architectural Features to Improve Sophisticated Denial-of-Service Attack Detections"],"prefix":"10.4018","volume":"4","author":[{"given":"Ran","family":"Tao","sequence":"first","affiliation":[{"name":"Louisiana State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Li","family":"Yang","sequence":"additional","affiliation":[{"name":"University of Tennessee at Chattanooga, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lu","family":"Peng","sequence":"additional","affiliation":[{"name":"Louisiana State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bin","family":"Li","sequence":"additional","affiliation":[{"name":"Louisiana State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jisp.2010010102-0","doi-asserted-by":"publisher","DOI":"10.1145\/762476.762477"},{"key":"jisp.2010010102-1","unstructured":"Chaturvedi, A., Bhatkar, E., & Sekar, R. (2006). Improving Attack Detection in Host-Based IDS by Learning Properties of System Call Arguments. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"jisp.2010010102-2","author":"Y.Chen","year":"2005","journal-title":"Collaborative Defense against Periodic. Shrew DDoS Attacks in Frequency Domain"},{"key":"jisp.2010010102-3","doi-asserted-by":"publisher","DOI":"10.1214\/aos\/1013203451"},{"key":"jisp.2010010102-4","unstructured":"Handley, M., Kreibich, C., & Paxson, V. (2001). Network Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics. In Proceedings of the USENIX Security Symposium (pp. 115-131)."},{"key":"jisp.2010010102-5","doi-asserted-by":"crossref","unstructured":"Hussain, A., Heidemann, J., & Papadopoulos, C. (2003). A Framework for Classifying Denial of Service Attack. In Proceedings of ACM SIGCOMM (pp. 99-110).","DOI":"10.1145\/863955.863968"},{"key":"jisp.2010010102-6","doi-asserted-by":"crossref","unstructured":"Jin, C., Wang, H., & Shin, K. G. (2003). Hop-Count Filtering: An Effective Defense against Spoofed Traffic. In Proceedings of the 10th ACM conference on Computer and Communications Security (pp. 30-41).","DOI":"10.1145\/948109.948116"},{"key":"jisp.2010010102-7","doi-asserted-by":"publisher","DOI":"10.1145\/1165389.945467"},{"key":"jisp.2010010102-8","doi-asserted-by":"crossref","unstructured":"Kuzmanovic, A., & Knightly, E. W. (2003). Low-Rate TCP-Targeted Denial of Service Attacks. In Proceedings of ACM SIGCOMM (pp. 75-86).","DOI":"10.1145\/863955.863966"},{"key":"jisp.2010010102-9","doi-asserted-by":"crossref","unstructured":"Lazarevic, A., & Kumar, V. (2005). Feature bagging for outlier detection. In Proceedings of the Eleventh ACM SIGKDD international Conference on Knowledge Discovery in Data Mining (pp. 157-166).","DOI":"10.1145\/1081870.1081891"},{"key":"jisp.2010010102-10","unstructured":"Lee, W., & Stolfo, S. (1998). Data mining approaches for intrusion detection. In Proceedings of the 7th USENIX Security Symposium, San Antonio, TX (pp. 79-94)."},{"key":"jisp.2010010102-11","doi-asserted-by":"crossref","unstructured":"Li, Y., & Guo, L. (2008). TCM-KNN scheme for network anomaly detection using feature-based optimizations. In Proceedings of the ACM Symposium on Applied Computing (pp. 2103-2109).","DOI":"10.1145\/1363686.1364194"},{"issue":"3","key":"jisp.2010010102-12","first-page":"1","article-title":"Towards integrating feature selection algorithms for classification and clustering.","volume":"17","author":"H.Liu","year":"2005","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"jisp.2010010102-13","unstructured":"Luo, X., & Chang, R. K. C. (2005). On a New Class of Pulsing Denial-of-Service Attacks and the Defense. In Proceedings of Network and Distributed System Security Symposium."},{"key":"jisp.2010010102-14","doi-asserted-by":"crossref","unstructured":"Moore, D., Voelker, G. M., & Savage, S. (2001). Inferring Internet Denial-of-Service Activity. In Proceedings of the 10th USENIX Security Symposium.","DOI":"10.21236\/ADA400003"},{"key":"jisp.2010010102-15","doi-asserted-by":"publisher","DOI":"10.1145\/1042031.1042036"},{"key":"jisp.2010010102-16","doi-asserted-by":"crossref","unstructured":"Savage, S., Wetherall, D., Karlin, A., & Anderson, T. (2000). Practical network support for IP traceback. In Proceedings of ACM SIGCOMM, Stockholm, Sweden (pp. 295-306).","DOI":"10.1145\/347057.347560"},{"key":"jisp.2010010102-17","doi-asserted-by":"crossref","unstructured":"Snoren, A. C., Partridge, C., Sanchez, L. A., Jones, C. E., Tchakountio, F., Kent, S. T., et al. (2001). Hash-based IP Traceback. In Proceedings of ACM SIGCOMM \u20192001, San Diego, CA (pp. 3-14).","DOI":"10.1145\/964723.383060"},{"key":"jisp.2010010102-18","doi-asserted-by":"crossref","unstructured":"Tao, R., Yang, L., Peng, L., Li, B., & Cemerlic, A. (2009). A Case Study: Using Architectural Features to Improve Sophisticated Denial-of-Service Attack Detections. In Proceedings of 2009 IEEE Symposium on Computational Intelligence in Cyber Security, Nashville, TN (pp. 13-18).","DOI":"10.1109\/CICYBS.2009.4925084"},{"key":"jisp.2010010102-19","doi-asserted-by":"crossref","unstructured":"Wagner, D., & Soto, P. (2002). Mimicry Attacks on Host-Based Inrusion Detection Systems, Proceedings of the 9th ACM conference on Computer and communications security, November 18\u201322, pp. 255 - 264","DOI":"10.1145\/586110.586145"},{"key":"jisp.2010010102-20","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2004.34"},{"key":"jisp.2010010102-21","unstructured":"Woo, D. H., & Lee, H.-H. S. (2007). Analyzing Performance Vulnerability due to Resource Denial-of-Service Attack on Chip Multiprocessors. In Proceedings of the 1st workshop on Chip-Multiprocessor Memory Systems and Interconnects (pp. 33-40)."},{"key":"jisp.2010010102-22","first-page":"1205","article-title":"Efficient Feature Selection via Analysis of Relevance and Redundancy.","volume":"5","author":"L.Yu","year":"2004","journal-title":"Journal of Machine Learning Research"},{"key":"jisp.2010010102-23","doi-asserted-by":"publisher","DOI":"10.1504\/IJCAT.2006.011994"}],"container-title":["International Journal of Information Security and Privacy"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=43055","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T23:08:58Z","timestamp":1654124938000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jisp.2010010102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2010,1,1]]},"references-count":24,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2010,1]]}},"URL":"https:\/\/doi.org\/10.4018\/jisp.2010010102","relation":{},"ISSN":["1930-1650","1930-1669"],"issn-type":[{"value":"1930-1650","type":"print"},{"value":"1930-1669","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010,1,1]]}}}