首页> 外文会议> >Native API Based Windows Anomaly Intrusion Detection Method Using SVM
【24h】

Native API Based Windows Anomaly Intrusion Detection Method Using SVM

机译:支持向量机的基于本机API的Windows异常入侵检测方法

获取原文

摘要

While many researches of Host Anomaly Detection System using system calls under UNIX/UNIX-like systems have been done but little in Windows systems, we do the similar research under Windows platforms via tracing the sequences of Windows Native APIs which are considered as the Windows system calls. In this article, we first introduce Native API briefly and then divide the captured sequences with slide window method to establish normal pattern database. Then Support Vector Machine Method is used for anomaly detection due to its advantages in small-scale dataset and generalization capability. The main purpose of this paper is to prove that Windows Native APIs are plausibly possible data source for Host Anomaly Detection System under Windows platforms.
机译:虽然在UNIX / UNIX的系统下使用系统调用的宿主异常检测系统的许多研究已经完成,但在Windows系统中很少,我们通过跟踪视为Windows系统的Windows本机API的序列,我们在Windows平台下进行类似的研究呼叫。在本文中,我们首先简要介绍本地API,然后用幻灯片窗口方法划分捕获的序列来建立正常模式数据库。然后支持向量机方法用于异常检测,因为它在小规模数据集中的优点和泛化能力。本文的主要目的是证明Windows本机API是Windows平台下主机异常检测系统的可编派可能的数据源。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号