摘要
从缓冲区溢出攻击的基本原理出发,对缓冲区溢出的主要攻击机制、攻击过程,及攻击所遗留踪迹作了概要介绍与总结,并在此基础上给出利用序列数据关联知识挖掘方法,通过对缓冲区溢出攻击所遗留下的踪迹日志的挖掘分析,来帮助发现这类攻击入侵行为的自动()检测方法。
This paper first introduces the principle of buffer overflow, and basic attacking method utilizing buffer overflow bugs, and intrusion process and intrusion traces. Sequence association data mining method about how to detect this kind of intrusion using log trace effectively is put forward. Data mining on log trace left by intrusion utilizing buffer overflow will help to find out network intrusion automatically. ;;
出处
《计算机工程》
CAS
CSCD
北大核心
2002年第7期152-152,269,共2页
Computer Engineering