A Resource-Aware Behavior Reconstruction and Hierarchical Semantic Learning Framework for Host Intrusion Detection

📅 2026-10-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge of extracting attack patterns from interleaved system call sequences by proposing ReSHID, a novel detection framework. The method introduces a resource-aware sequence reconstruction technique based on bipartite matching to recover continuous behavioral semantics. By integrating file descriptor lifecycle tracking, it constructs subject graphs and employs GATv2 graph neural networks with hierarchical semantic learning to capture multi-subject collaborative attack features, ultimately achieving efficient discrimination via a lightweight linear classifier. Experimental results demonstrate that ReSHID attains an F1 score of 98.64% and a ROC-AUC of 99.80%, while reducing n-gram features by 75.2%. Its overall performance significantly surpasses that of existing methods.
📝 Abstract
System calls (syscalls) record key interactions between running programs and the operating system kernel, providing fine-grained and minimally intrusive data for host-based intrusion detection systems (HIDS) deployed in cloud and other modern computing environments. However, existing methods often model syscalls in their original execution order, where sequences from different processes are interleaved, making informative patterns difficult to extract and raising two questions: whether raw syscall sequences can be reorganized in a way that yields more discriminative representations, and how complex attack patterns can be effectively learned from the reorganized sequences. We propose ReSHID, a resource-aware behavior reconstruction and hierarchical semantic learning framework for host intrusion detection. It reconstructs semantically continuous sequences by leveraging syscall semantic invariants to cast subject identity and relationship resolution across PID namespaces as a bipartite matching problem and tracking file descriptor (FD) lifecycles to associate descriptors referring to the same resource. Additionally, features extracted from these sequences are organized into a lightweight subject behavior graph incorporating inter-subject relationships, where GATv2 captures key coordination patterns to model complex attacks involving multiple subjects. Experimental results show that sequence reconstruction combined with the detection method can improve HIDS performance. Even with a lightweight linear classifier, the proposed method achieves the best results among all compared methods in terms of F1-score (98.64%), ROC-AUC (99.80%), and PR-AUC (98.10%), while reducing the number of n-gram features by approximately 75.2% and 44.1% compared with the raw sequences and MGFE, respectively.
Problem

Research questions and friction points this paper is trying to address.

Host Intrusion Detection
System Calls
Behavior Reconstruction
Attack Pattern Learning
Innovation

Methods, ideas, or system contributions that make the work stand out.

Behavior Reconstruction
Hierarchical Semantic Learning
Bipartite Matching
Graph Attention Network
Host Intrusion Detection
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Y
Youli Tao
School of Cyber Science and Engineering, Sichuan University, Chengdu, Sichuan 610065, China
Rui Tang
Rui Tang
Assistant Researcher of Cyber Science and Engineering, Sichuan University
AI securitySecurity for LLMsAdversarial attacksSocial network analysis.
Hao Ren
Hao Ren
MPhil Student, University of New South Wales
Graph Neural NetworkNeural ODEsDeep Learning
C
Chengsheng Zhou
School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing, 100876, China; Institute of Security, China Academy of Information and Communications Technology, Beijing, 100191, China
D
Dengzhe Wang
School of Cyber Science and Engineering, Sichuan University, Chengdu, Sichuan 610065, China
Shuyu Jiang
Shuyu Jiang
Assistant Researcher of School of Cyber Science and Engineering, Sichuan University
Social Network AnalysisNatural Language GenerationLarge Language Models
Xingshu Chen
Xingshu Chen
Professor of Computer Science, Sichuan University
Cybersecurity