首页> 外文会议>2010 2nd International Conference on e-Business and Information System Security (EBISS2010) >An Intrusion Detection Approach Based on System Call Sequences and Rules Extraction
【24h】

An Intrusion Detection Approach Based on System Call Sequences and Rules Extraction

机译:基于系统调用序列和规则提取的入侵检测方法

获取原文
获取原文并翻译 | 示例

摘要

Intrusion detection systems protect normal users and system resources from information security threats. Anomaly detection is an approach of intrusion detection that constructs models of normal behavior of users or systems and detects the behaviors that deviate from the model. Monitoring the sequences of system calls generated during the execution of privileged programs has been known to be an effective means of anomaly detection. In this paper, an approach for anolymal intrusion detection is presented and applied to monitor the abnormal behavior of processes. The approach is based on rough set theory and capable of extracting a set of rules with the minimum size to form a normal behavior model from the record of system call sequences generated during the normal execution of a process. It may detect the abnormal operating status of a process. The normal behavior model in terms of the system call sequences is defined. And the detection algorithm is given for the application of rough set theory in intrusion detection. The illustrative example shows that it is feasible and effective.
机译:入侵检测系统可保护普通用户和系统资源免受信息安全威胁。异常检测是一种入侵检测方法,可构造用户或系统正常行为的模型并检测与模型偏离的行为。监视特权程序执行期间生成的系统调用序列是已知的一种异常检测的有效方法。在本文中,提出了一种用于分析异常入侵的方法,并将其应用于监视过程的异常行为。该方法基于粗糙集理论,并且能够从在正常执行过程中生成的系统调用序列的记录中提取具有最小大小的规则集以形成正常行为模型。它可能会检测到进程的异常运行状态。根据系统调用顺序定义了正常行为模型。给出了将粗糙集理论应用于入侵检测的检测算法。说明性的例子表明,它是可行和有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号