期刊文献+

一种基于行为分析的程序异常检测方法 被引量:4

Program anomaly detecting approach based on behaviors analysis
下载PDF
导出
摘要 从系统资源保护的角度出发,分析并归纳了进程访问资源的异常行为特征,提出了一种基于行为分析的程序异常检测方法。该方法通过在运行的系统上设置资源防护检查点,采用用户模式API拦截技术实时检测进程操作资源的行为,并运用贝叶斯算法对程序行为特征作组合分析,发现异常时进行告警。 For the purpose of protecting system resource, process behaviors anomaly at runtime was analyzed and summarized, and a program anomaly detection approach was put forward based on behaviors analysis. By setting check-points on running system, API hook under user-mode was used to detect process behaviors on operating resources, and Bayes algorithm was used to estimate the validity of program behaviors. An alarm would be given when detecting anomaly.
出处 《计算机应用》 CSCD 北大核心 2008年第10期2492-2494,共3页 journal of Computer Applications
关键词 系统资源 进程 行为特征 拦截 贝叶斯算法 system resource process behavioral characteristics hook Bayes algorithm
  • 相关文献

参考文献6

二级参考文献34

  • 1张璠.多种策略改进朴素贝叶斯分类器[J].微机发展,2005,15(4):35-36. 被引量:11
  • 2周顺先,陈浩文,池鹏.一种基于资源操作域的主机防护模型[J].计算机工程与应用,2006,42(5):152-155. 被引量:4
  • 3Gao Yan.The Research and Implement of systematic protected technology for limited system[D].Academic dissertation.
  • 4Liu Baoxiu,Xu Rongsheng.Classified studies of Hacker's Attack Behaviors[J].Network Security Technology and Application ,2003 ; (4).
  • 5Anthony Mason.Windows NT Device Driver Development.Peter Viscarola.
  • 6James Finnegan.How to notify user-mode applications asynchronously from kernel mode[J],MSJ, 1999-07.
  • 7R Sekar,T Bowen,M Segal.On Preventing Intrusions by Process Behavior Monitoring.
  • 8Pu,Perry Wagle,Virgil Gligor.Parsimonious Server Security[C],In: Crispin Cowan,Steve Beattie,Greg Kroah-Hartman,Calton eds.The USENIX LISA 2000 Conference.
  • 9Yona Hollander,Romain Agostini.Stop Hacker Attacks at the OS Level[J].INTERNET SECURITY ADVISOR - SEPTEMBER/OCTO- BER,2000, (5).
  • 10Preventing Attacks to the Host Iain Franklin Information Security. Bulletin CHI Publishing Ltd.

共引文献29

同被引文献13

引证文献4

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部