摘要
借鉴Unix类系统下基于系统调用的主机异常检测理论,通过追踪Windows本机应用编程接口调用序列,对Windows系统下的主机异常检测进行研究.在异常序列检测中,结合使用对小数据集具有较好推广能力的支撑矢量机方法,进而取得较高的检测准确率.实验表明Native API可为Windows平台下基于主机的异常检测系统提供一种可能的数据源.
According to the study of host abnormal detection based on system calls under UNiX-like systems, this paper completes the similar research via tracing the sequences of Windows Native APIs (Application Programming Interfaces, APIs) under Windows platform. In the process of abnormal sequence detection, the SVM(Support Vector Machine) method is used for its generalization capability in small-scale dataset and a high accuracy of detection is obtained. The experimental results show that Windows Native APIs are possible data source for the host abnormal detection system under Windows platform.
出处
《陕西师范大学学报(自然科学版)》
CAS
CSCD
北大核心
2007年第4期37-40,共4页
Journal of Shaanxi Normal University:Natural Science Edition
关键词
异常检测
支撑矢量机
Windows本机应用编程接口
abnormal detection
support vector machine (SVM)
Windows native application programming interface (API)