摘要
主机日志在入侵检测中有着不可替代的作用,通过深入分析主机日志可以发现系统的异常行为。该文分析了主机日志的构成,主机日志在计算机安全领域中的应用,并给出了常用的主机日志和基于主机日志的入侵检测系统。主机日志的分析方法有很多,文章对这些方法进行了分类并对它们进行了详细的讨论。最后,给出了一种基于主机日志分析的入侵检测通用模型。
Host audit trails are very valuable in the fi el ds of Intrusion Detection.From their analysis you can identify host abnormality .This paper describes host audit trails,their uses and applications of their a nalysis to intrusion detection.There exists many methods for analysis of host a udit trails,these methods are classified and discussed in this paper.Finally, a general model is presented and result of its employment has proved that it is very valuable for intrusion detection analysis.
出处
《计算机工程与应用》
CSCD
北大核心
2002年第13期35-37,179,共4页
Computer Engineering and Applications
基金
国家863高技术发展研究计划(编号:2001AA140213)
国家杰出青年基金(编号:6970025)
关键词
主机日志分析
入侵检测
计算机网络
网络安全
Audit trails,Intrus ion detection,computer security,anomaly detection