@inproceedings{SisLab3379, booktitle = {H?i th{\h a}o l?n th? III M?t s? v?n {\dj}? ch{\d o}n l{\d o}c v? an to{\`a}n an ninh th{\^o}ng tin}, title = {Ph{\'a}t hi?n m{\~a} {\dj}?c tr{\^e}n c{\'a}c thi?t b{\d i} IoT d?a tr{\^e}n l?i g{\d o}i Syscall v{\`a} ph{\^a}n lo{\d a}i m?t l?p SVM}, author = {Nghi Phu Tran and Quoc Dung Ngo and Dang Kien Hoang and Ngoc Binh Nguyen and Dai Tho Nguyen}, year = {2018}, url = {https://eprints.uet.vnu.edu.vn/eprints/id/eprint/3379/}, abstract = {- Ma? {\dj}{\d o}?c tre?n ca?c thi{\^e}?t bi? Va?n v{\d a}?t k{\^e}?t n{\^o}?i Internet - Internet of Things (IoT), tha?nh ph{\^a}?n c{\^o}?t lo?i trong cu{\d o}?c ca?ch ma?ng 4.0, {\dj}ang nga?y ca?ng ta?ng nhanh. Ca?c thi{\^e}?t bi? IoT co? ki{\^e}?n tru?c MIPS chi{\^e}?m ti? l{\d e}? l??n, song ca?c nghie?n c??u pha?t hi{\d e}?n ma? {\dj}{\d o}?c d??a tre?n ha?nh vi cu?a ca?c thi{\^e}?t bi? na?y chu?a {\dj}u???c {\dj}{\^e}? c{\d a}?p. Chu?ng to?i {\dj}{\^e}? xu{\^a}?t quy tri?nh pha?n ti?ch pha?t hi{\d e}?n ma? {\dj}{\d o}?c trong ca?c thi{\^e}?t bi? IoT s?? du?ng ki{\^e}?n tru?c MIPS d??a tre?n l??i go?i h{\d e}? th{\^o}?ng syscall (hay system call) b{\u a}?ng ky? thu{\d a}?t pha?n loa?i m{\d o}?t l??p SVM. Ca?c chu?o?ng tri?nh {\dj}u???c cha?y trong C500-Sandbox {\dj}{\^e}? thu th{\d a}?p ca?c syscall {\dj}u???c go?i, ca?c syscall {\dj}u???c bi{\^e}?u di{\^e}?n du???i da?ng {\dj}{\d a}?c tru?ng n-gram, sau {\dj}o? s?? du?ng phu?o?ng pha?p pha?n ti?ch tha?nh ph{\^a}?n chi?nh (Principal Component Analysis - PCA) {\dj}{\^e}? gia?m s{\^o}? chi{\^e}?u tru???c khi {\dj}u???c hu{\^a}?n luy{\d e}?n/nh{\d a}?n da?ng b{\u a}?ng mo? hi?nh pha?n loa?i m{\d o}?t l??p SVM (One class SVM). Quy tri?nh cho k{\^e}?t qua? pha?t hi{\d e}?n t{\^o}?t v??i chi? s{\^o}? F-Score (F1) = 0,976, Average precision (AP) = 0,992, Accuracy (AC) = 0,956.} }