期刊文献+

基于AEC的恶意代码检测系统的设计与实现 被引量:3

Design and implementation of malicious code detection system based on AEC
下载PDF
导出
摘要 针对现有恶意代码检测技术的不足,提出了能够有效检测复杂攻击的活动事件关联(AEC)分析技术,设计并实现了一个基于AEC的全新的检测系统。该系统结合误用与异常检测技术,采用AEC的思想将网络中的单个事件进行分类,对每类事件进行纵向关联分析。同时结合一段时间内的数据流量统计结果,最终更准确地推断出可疑的攻击并在它们完成攻击前阻止,向网络管理员发出有意义的准确的报警。 In order to deal with the deficiency of current malicious code detection methods, an efficient detection method AEC for Multi-stage attack was proposed, and a new detection system based on AEC was designed and implemented. This system combined the misuse detection with anomaly detection methods, classified the single event in the network based on Active Event Correlation (AEC), and correlatively analysed each sort of events. Meanwhile, statistical model was used for further analysis. At last, it can effectively recognize multi-stage attacks, stop incomplete attack stages, and give network administrators meaningful and concise alerts.
出处 《计算机应用》 CSCD 北大核心 2007年第6期1371-1373,1377,共4页 journal of Computer Applications
关键词 误用检测 异常检测 活动事件关联检测 流量统计 misuse detection anomaly detection Active Event Correlation (AEC) detection traffic statistic
  • 相关文献

参考文献5

  • 1VALDES A,SKINNER K.Probabilistic alert correlation[A].In Proc.of Recent Advances in Intrusion Detection (RAID 2001),Springer LNCS 2212[C].Davis,CA,USA,October 2001.
  • 2CUPPENS F,MIGE A.Alert correlation in a cooperative intrusion detection framework[A].In Proc.of the 2002 IEEE Symposium on Security and Privacy[C].May 2002.
  • 3MORIN B,DEBAR H.Correlation of intrusion sysmptoms:an application of chronicles[A].In Proc.of the 6th International Symposium on Recent Advances in Intrusion Detection[C].Pittsburgh,PA,September 2003.
  • 4ELKAN C.Results of the KDD' 99 Classifier Learning Contest[EB/OL].http://www-cse.ucsd.edu/users/elkan/clresuhs.html,2006.
  • 5LEE W,STOLFO SJ,MOK KW.A data mining framework for building intrusion detection models[A].In:The 1999 IEEE Symposium on Security and Privacy[C].Oakland,CA,1999.

同被引文献24

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部