摘要
linux系统调用信息对于描述主机系统的安全状态有重要的作用,论文分析了linux系统调用信息在入侵检测中的应用;阐述了入侵检测系统HostKeeper中系统调用传感器的原形框架、软件设计和实现方法;并给出了利用linux系统调用信息进行入侵检测的实验结果。
The information of linux system call plays an important role in describing the security state of computer system.There are more and more attentions put in this research area.This paper analyzes the utility of system call infor-mation in intrusion detection,discusses the prototype architecture,software design and realizing method of system call sensor in intrusion detection system HostKeeper,and gives the experiment result of HostKeeper in intrusion detection.
出处
《计算机工程与应用》
CSCD
北大核心
2003年第26期119-121,128,共4页
Computer Engineering and Applications
基金
国家863高技术研究发展计划(编号:2001AA140213)资助