期刊文献+

一种基于LSM的数据源在异常检测中的应用

Application of LSM-Based Data Source on Anomaly Detection
下载PDF
导出
摘要 针对异常检测中的数据源选择、行为描述、正常行为学习和行为匹配,提出了一种新的基于安全模块的数据源。为验证其有效性,采用基于信息理论的数据分析和马尔可夫模型两种方法,并与目前较多采用的系统调用数据源作了对比。实验结果表明,新数据源有效,且在一定条件下,比系统调用数据更具优势。 The research of anomaly detection now focuses on four aspects: selection of data source, specification of behavior, normal behavior learning, behavior matching. For the first aspect, a new data source, which is based on linux security modules, is presented in paper. In order to test its effect, we employ two kinds of method: information-theoretic measures and Markov chains model, and we also compare the result with data of system call. The conclusion of experiment indicates that this data source is useful and even better than data of system call under certain condition.
作者 张衡 张毓森
出处 《电子科技大学学报》 EI CAS CSCD 北大核心 2004年第4期403-406,共4页 Journal of University of Electronic Science and Technology of China
基金 国家863计划资助项目(2002AA141090)
关键词 异常检测 行为控制 安全模块 系统调用 anomaly detection behavior control linux security modules system call
  • 相关文献

参考文献5

  • 1[1]Forrest S, Hofmeyr S A, Somayaji A, et al. A sense of self for unix processes[C]. In: Proceedings of the 1996 IEEE Symposium on Security and Privacy, Los Alamitos, 1996. 120-128
  • 2[2]Hofmeyr S A, Forrest S, Somayaji A. Intrusion detection using sequences of system calls[J]. Journal of Computer Security, 1998(6): 151-180
  • 3[3]Wright C, Cowan C, Morris J, et al. Linux Security Modules: general security support for the Linux kernel[C]. In: USENIX Security Symposium, San Francisco, 2002. 17-31
  • 4[4]Wenke Lee, Dong Xiang. Information-theoretic measures for anomaly detection[C]. In the 2001 IEEE Symposium on Security and Privacy, Oakland, 2001. 130-143
  • 5[5]Nong Ye. A markov chains model of temporal behavior for anomaly detection[C]. In: Proceedings of the 2000 IEEE Workshop on Information Assurance and Security, West Point, United States Military Academy, 2000. 171-174

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部