期刊文献+

基于K-Nearest Neighbor分类算法的异常检测模型

An anomaly detection model based on K-nearst neighbor classification algorithm
下载PDF
导出
摘要 入侵检测成了信息安全中不可缺少的安全措施 ,而异常检测是入侵检测研究中的热点 .提出了一种新的异常检测算法 ,用 K- Nearest Neighbor分类算法对特权程序 (或进程 )的系统调用进行分析 ,通过计算系统调用出现的频度判断进程是否异常 .测试表明 ,该方法具有良好的检测性能和较低的误报率 ,占用的系统资源较少 。 Intrusion detection becomes one of essential information security measures, and the research of intrusion detection focuses on anomaly detection. A new anomaly detection algrithm is proposed. It analyzes the system calls of privileged process through K-nearest neighbor classification algorithm, and it decides whether the process is abnormal by computing the frequency of the system calls. The test result shows that the algorithm is reasonable and feasible for it has good detecting performance and lower false positive rate and it costs a little.
作者 宋辛科
出处 《西安石油大学学报(自然科学版)》 CAS 2004年第2期77-79,共3页 Journal of Xi’an Shiyou University(Natural Science Edition)
关键词 异常检测模型 分类算法 特权进程 网络安全 安全措施 入侵检测 信息安全 检测性能 anomaly detection algorithm system call privileged process network safety
  • 相关文献

参考文献7

  • 1[1]vaccaro H S, Liepins G E. Detection of anomalous computer session Activity[C]. Proceedings of 1989 IEEE Symposium on Security and Privacy, 1989. 280-289.
  • 2[2]Yeung Dit-Yan, Ding Yuxin. Host-based intrusion detection using dynamic and static behavioral models [J]. Pattern Rcognition ,2003, (36): 229-243.
  • 3[3]Niels Provos. Improving Host Security with System Call Policies [EB/OL]. http://www. citi. umich. edu/techreports/reports, 2002.
  • 4[4]Joao B D, Cabrera L L. Detection and Calssification of Intrusions and Faults using, Sequences of System Calls [EB/OL]. http ://www. cs. columbia. edu/ids/research/keypapers / papers/security, 2001.
  • 5[5]Steven A H,Stephanie F. Intrusion Detection using Sequences of System Calls [EB/OL]. http ://www.cs. unm. edu/~steveah, 1998.
  • 6[6]Aas K, Eikvil L. Text Categorisation: A Sruvey[EB/OL]. http://citeseer. jn. nec. com/, 1999.
  • 7[7]Kwok J T-Y. Automatic Text Categorization Using Support Vector Machine [ C ]. Proceedings of International Conference on Neural Information Processing, 1998. 347-351.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部