期刊文献+

基于IRP特征序列的文件行为监控模型 被引量:1

File Monitoring Model Based on IRP Feature Sequence
下载PDF
导出
摘要 随着信息技术的广泛应用,要害部门和机构对敏感机密文件的保护也越来越重视。现有的监控技术很难发现具有危害的文件操作行为。在对中间层驱动进行分析的基础上,提出了基于IRP序列的文件行为监控模型,并解决了IRP信息的异步提取、序列跟踪和行为判定方法等关键问题,提高了文件行为监控的覆盖率和判定的准确性。对比实验验证了提出方法的有效性和准确性。 With the extensive application of information technology, key organizations pay increasing attention to the protection of sensitive or confidential files. But existing monitoring techniques can hardly find harmful file operations. After the analysis of the intermediate driver, a file monitoring model based on the IRP feature sequence is proposed. With this model, key issues such as the asyn-chronous extraction of IRP feature information, sequence tracking and operation judging can be solved effectively, which means improved file monitoring coverage and judgment accuracy. Compar-ative experiments demonstrate the validity and accuracy of the proposed method.
出处 《信息工程大学学报》 2012年第4期508-512,共5页 Journal of Information Engineering University
基金 河南省重大科技攻关专项资助项目(092101210501)
关键词 中间层驱动 文件行为 IRP特征序列 数据库 神经网络 intermediate driver file action IRP feature sequence database neural network
  • 相关文献

参考文献5

二级参考文献19

  • 1ONEYW. Programming the Microsoft Windows driver model[M]. 2nd ed. Washington: Microsoft Press, 2002.
  • 2Microsoft Corporation. Microsoft Windows 2000 driver development kit[ M]. Washington: Microsoft Press, 2000.
  • 3NAGAR R. Windows NT file system internals [M]. New York : O'Reilly and Associates, 1998.
  • 4BAKER A, LOZANO J. Windows2000 设备驱动程序设计指南[M].施诺,译.北京:机械工业出版社,2001.
  • 5CANTC.Writing Windows WDM device drivers[M].孙义译.北京:机械出版社,2000.
  • 6BAKER A, LOZANO J. The Windows 2000 device driver book [M]. [ S. l. ] : Prentice Hall PTR, 2001.
  • 7AWAN M A, KHIYAL S H. Staekably extensible template layer for file system development under Windows NT[C]// E-Tech 2004. New York: IEEE, 2004:74 - 82.
  • 8GLUND G, BUTLER J. Rootkits: Subverting the Windows kernel [M]. New York: Addison Wesley, 2005.
  • 9Power R.2002 CSI/FBI Computer Crime and Security Survey[Z].San Francisco:American Computer Security Institute,2002.
  • 10Richter J.Programming Applications for Microsoft Windows[M].[S.l.]:Microsoft Press,2000.

共引文献19

同被引文献8

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部