Research Article

A Host-Based Anomaly Detection Framework Using XGBoost and LSTM for IoT Devices

Table 1

Five classes of collected system call sequence dataset.

No.Class nameStateNotes

1Class 0Normal stateSyscall sequence data in normal state
2Class 1Vulnerability exploitingSyscall sequence data in CVE-2016-5195
3Class 2Malware infectionSyscall sequence data in BASHLITE malware
4Class 3Abnormal operationSyscall sequence data in user add operation
5Class 4Memory leakSyscall sequence data in RTSP memory leak