🤖 AI Summary
This study addresses the challenge of extracting attack patterns from interleaved system call sequences by proposing ReSHID, a novel detection framework. The method introduces a resource-aware sequence reconstruction technique based on bipartite matching to recover continuous behavioral semantics. By integrating file descriptor lifecycle tracking, it constructs subject graphs and employs GATv2 graph neural networks with hierarchical semantic learning to capture multi-subject collaborative attack features, ultimately achieving efficient discrimination via a lightweight linear classifier. Experimental results demonstrate that ReSHID attains an F1 score of 98.64% and a ROC-AUC of 99.80%, while reducing n-gram features by 75.2%. Its overall performance significantly surpasses that of existing methods.
📝 Abstract
System calls (syscalls) record key interactions between running programs and the operating system kernel, providing fine-grained and minimally intrusive data for host-based intrusion detection systems (HIDS) deployed in cloud and other modern computing environments. However, existing methods often model syscalls in their original execution order, where sequences from different processes are interleaved, making informative patterns difficult to extract and raising two questions: whether raw syscall sequences can be reorganized in a way that yields more discriminative representations, and how complex attack patterns can be effectively learned from the reorganized sequences. We propose ReSHID, a resource-aware behavior reconstruction and hierarchical semantic learning framework for host intrusion detection. It reconstructs semantically continuous sequences by leveraging syscall semantic invariants to cast subject identity and relationship resolution across PID namespaces as a bipartite matching problem and tracking file descriptor (FD) lifecycles to associate descriptors referring to the same resource. Additionally, features extracted from these sequences are organized into a lightweight subject behavior graph incorporating inter-subject relationships, where GATv2 captures key coordination patterns to model complex attacks involving multiple subjects. Experimental results show that sequence reconstruction combined with the detection method can improve HIDS performance. Even with a lightweight linear classifier, the proposed method achieves the best results among all compared methods in terms of F1-score (98.64%), ROC-AUC (99.80%), and PR-AUC (98.10%), while reducing the number of n-gram features by approximately 75.2% and 44.1% compared with the raw sequences and MGFE, respectively.