期刊文献+

基于系统调用的日志系统的设计与实现 被引量:7

A log system based on system call
下载PDF
导出
摘要 为提高Linux系统安全性,在逐步分析Linux系统调用机制的基础上,设计并实现了基于系统调用的日志系统。通过在内核添加新的系统调用,从内核实时截获日志信息,并导出到用户态,使系统能够实时获取与系统安全相关的各种信息,从而分析系统的行为,审计系统的安全性。为尽可能减少内核代码的修改,核心功能模块以内核可加载模块机制实现,减少了调试难度,加大了系统的可扩充性。 In order to analyze the system's security easily and timely,the Linux system call mechanism is studied and a log system based on system call is designed and implemented.By this design,new system calls are added to the kernel,form which logs are captured and exported to the user mode part in real-time.To reduce the modification of kernel source as much as possible,the core function module is designed as kernel loadable module,which also brings the debugging difficulty to be lower and makes the system extend easier.
出处 《西安邮电学院学报》 2011年第4期59-61,65,共4页 Journal of Xi'an Institute of Posts and Telecommunications
关键词 LINUX内核 系统调用 日志系统 Linux kernel system call log system
  • 相关文献

参考文献4

  • 1倪继利.Linux内核分析及编程[M].北京:电子工业出版社,2006.
  • 2Robert Love.1inux内核设计与实现EM].第2版.陈莉君,康华,张波译.北京:机械工业出版社,2006.
  • 3The Linux Kernel Organization. linux 内核源码 [ EB/ OL]. (2010-04-26) [2010-12-25]. http.//www, kernel. org/pub/linux/kernel/v2. 6/.
  • 4Intel Corporation. 253668-034US, Intel 64 and IA-32 Architectures Software Developer's Manual[S].

共引文献3

同被引文献59

  • 1陈莉君.Linux内核的分析及应用[J].西安邮电学院学报,2001,6(1):17-20. 被引量:9
  • 2LI Xianghe ZHANG Liancheng LI Shuo.Kernel Rootkits Implement and Detection[J].Wuhan University Journal of Natural Sciences,2006,11(6):1473-1476. 被引量:2
  • 3Love R.Linux内核设计与实现[M].陈莉君,译.北京:机械工业出版社,2006.
  • 4StevensWR,RagoSA.UNIX环境高级编程[M].尤晋元,张亚英,戚正伟,译.北京:人民邮电出版社,2006:287-329.
  • 5Daniel P.Bovet,Marco Cesati.深入理解LINUX内核[M].北京:中国电力出版社,2004.
  • 6Heidari P,Desnoyers M,Dagenais R M.Virtual Sys-tems Tracing for Performance Analysis[J].The OpenCybernetics and Systemics Journal,2011,5(2):1-4.
  • 7Stevens W R,Fenner B,RUDOFF A M.Unix网络编程(卷1):套接字联网API[M].杨继伟,译.北京:人民邮电出版社,2010:92.
  • 8Nokia Corporation.What is Qt?[EB/OL].(2005-11-01)[2012-04-12].http://qt.nokia.com.
  • 9Streicher M.Monitor file system activity with inotify.[EB/OL].(2008-09-16)[2012-04-12].http://www.ibm.com/developerworks/linux/library/l-ubuntu-ino-tify/index.html?S_TACT=105AGX52&S_CMP=cn-a-l.
  • 10XIA Ying,Fairbanks K,Owen H.A program behaviormatching architecture for probabilistic file system fo-rensics[J].ACM SIGOPS Operating Systems Review,2008,42(3):4-13.

引证文献7

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部