摘要
针对异常入侵检测存在的准确性差、速度慢的问题,提出一种基于句法模式识别的异常检测技术。该方法将句法模式识别技术应用到入侵检测中,通过该技术对结构的强大描述和识别能力,提高入侵检测的准确性和速度;描述了如何用句法模式识别技术建立程序执行的正常模型,以及如何使用模型检测入侵;并通过实验,验证了方法的有效性。
A new anomaly intrusion detection method based on structure pattern recognition is proposed so as to improve the accuracy and speed of anomaly detection. The method applies the structure pattern recognition technique to intrusion detection. Because of the powerful ability of description and identification in the technique, the accuracy and speed are enhanced. This paper describes how the structure pattern recognition technique is used to establish the normal mode in the program execution, and how this model is used in intrusion detection. The effectiveness of this method is proved by the experiments.
出处
《合肥工业大学学报(自然科学版)》
CAS
CSCD
北大核心
2008年第5期708-710,共3页
Journal of Hefei University of Technology:Natural Science
关键词
异常入侵检测
系统调用序列
句法模式识别
anomaly intrusion detection
sequence of system calls
structure pattern recognition