摘要
提出了一种分为业务层和共用支撑模块层的安全审计代理系统技术架构两层模型,介绍了进程隐藏和异常恢复等增强审计代理在目标主机存活能力的技术手段。通过在共用支撑模块中提供各类可配置的通用功能和安全模块,简化了审计代理系统的实现,提高了审计代理在目标主机的存活能力。
A two-layered technical model of security audit agent system is presented. The model is composed of operation layer and common supporting layer. Some technologies, such as process hiding and failure recovery, can strengthen the viability of audit agent in the target host. According to the kinds of configurable common functions and security modules of the common supporting layer, we could design an audit agent more easily, and improve the viability of the agent.
出处
《中国电子科学研究院学报》
2009年第1期63-66,共4页
Journal of China Academy of Electronics and Information Technology
关键词
审计代理
共用支撑模型
进程隐藏
异常恢复
audit agent
common supporting model
process hiding
failure recovery