Research Article

Anomaly Detection of System Call Sequence Based on Dynamic Features and Relaxed-SVM

Table 4

ADFA-LD and UNM dataset, the results for different models.

DatasetAlgorithmAUCF1-scoreFalse alarm rate

ADFA-LDEWR-SVM99%0.932.4%
Naive Bayes94%0.908%
Logistic regression96%0.943%
Random forest98%0.927%
GBDT98%0.944%

UNMEWR-SVM97%0.830%
Naive Bayes89%0.360%
Logistic regression95%0.7210%
Random forest97%0.830%
GBDT97%0.80%