期刊文献+

GECISM中“缓冲溢出类非我”的识别

Detection of Buffer-OverFlow Based on GECISM
下载PDF
导出
摘要 缓冲区溢出攻击技术目前是一项广泛而基础的攻击技术,也是目前攻击技术的主要发展方向。缓冲溢出攻击常用手段就是通过改变程序的执行流程,转而去执行其植入的入侵代码,进而获得系统的root权限,对系统安全构成了巨大的威胁。该文在模仿生物免疫系统设计的计算机安全系统模型GECISM基础上构建了DAE Agent。通过RC4.5算法实对入侵训练集的系统调用序列进行规则提取,从而此代理实现了对缓冲溢出类入侵的检测。 Buffer-Overflow attacks has been the common and basic attack technology,and nowadays it is also the main direction of attack technology.The common method of buffer-overflow is to change the order of program execution in order to execute the code which is written by intruder.By this way,intruder can get the root access,and it willtake great threat to the system. The article constructs the DAE(Detecting and Eliminating)on the GECISM.The agent can detect intrusion with the rule which is formed by the RC4.5 Algorithm.
出处 《微型电脑应用》 2009年第8期47-49,6,共3页 Microcomputer Applications
关键词 缓冲溢出 系统调用 DAE AGENT 识别 GECISM Buffer-Overflow System-Call DAE agent Detection GECISM
  • 相关文献

参考文献9

二级参考文献38

  • 1童竞亚.医学免疫学与微生物学(第三版)[M].北京:人民卫生出版社,1996.208.
  • 2Hu Keyun,Proceedings of PAKDD-99[C],1999年,109页
  • 3Hu Keyun,Proceedings of RSFDGr C99,1999年,443页
  • 4王志海,清华大学学报,1998年,38卷,增2期,14页
  • 5Ho T B,KDD:Techniques and Applications,1997年,49页
  • 6Ho T B,IEICE Trans Inf Syst,1995年,E78-D卷,5期,553页
  • 7Debar H, Dacier M, Wespi A. Toward a taxonomy of intrusion-detection systems. Computer Networks, 1999,31(8):805-822.
  • 8Ye N, Li XY, Chen Q, Emran SM, Xu MM. Probabilistic techniques for intrusion detection based on computer audit data IEEE Trans. on Systems, Man, and Cybernetics-Part A: Systems and Humans, 2001,31(4):266-274.
  • 9Ko C, Fink G, Levitt K. Automated detection of vulnerabilities in privileged programs byexecution monitoring. In: Proc. of the 10th Annual Computer Security Applications Conf Orlando: IEEE Computer Society Press 1994. 134~144.
  • 10Bernaschi M, Gabrielli E, Mancini LV. REMUS: A security-enhanced operating system. ACM Trans. on Information and System Security, 2002,5(1):36-61.

共引文献164

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部