首页> 外文会议>Computational Intelligence in Cyber Security, 2009. CICS '09 >A case study: Using architectural features to improve sophisticated denial-of-service attack detections
【24h】

A case study: Using architectural features to improve sophisticated denial-of-service attack detections

机译:案例研究:使用体系结构功能来改进复杂的拒绝服务攻击检测

获取原文

摘要

Application features such as port numbers are used by network-based intrusion detection systems (NIDSs) to detect attacks coming from networks. System calls and the operating system related information are used by host-based intrusion detection systems (HIDSs) to detect intrusions towards a host. However, the relationship between hardware architecture events and denial-of-service (DoS) attacks has not been well revealed. When increasingly sophisticated intrusions emerge, some attacks are able to bypass both the application and the operating system level feature monitors. Therefore, a more effective solution is required to enhance existing HIDSs. In this paper, we identify the following hardware architecture features: instruction count, cache miss, bus traffic and integrate them into a novel HIDS framework based on a modern statistical gradient boosting trees model. Through the integration of application, operating system and architecture level features, our proposed HIDS demonstrates a significant improvement of the detection rate in terms of sophisticated DoS intrusions.
机译:基于网络的入侵检测系统(NIDS)使用端口号等应用程序功能来检测来自网络的攻击。基于主机的入侵检测系统(HIDS)使用系统调用和与操作系统相关的信息来检测对主机的入侵。但是,硬件体系结构事件与拒绝服务(DoS)攻击之间的关系尚未得到很好的揭示。当越来越复杂的入侵出现时,某些攻击能够绕过应用程序和操作系统级别的功能监视器。因此,需要一种更有效的解决方案来增强现有的HIDS。在本文中,我们确定了以下硬件体系结构功能:指令计数,高速缓存未命中,总线流量,并将它们集成到基于现代统计梯度增强树模型的新型HIDS框架中。通过集成应用程序,操作系统和体系结构级别的功能,我们提出的HIDS证明了在复杂的DoS入侵方面检测率的显着提高。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号