首页> 外文会议>Information and Communications Security >A Useful Intrusion Detection System Prototype to Monitor Multi-processes Based on System Calls
【24h】

A Useful Intrusion Detection System Prototype to Monitor Multi-processes Based on System Calls

机译:一个有用的基于系统调用监视多进程的入侵检测系统原型

获取原文

摘要

Based on studying of process behaviors classification, a practical intrusion detection system prototype is discussed. As one of the key elements, the system behaviors classifier (Naive Bayesian Classifier) can identify malicious system behaviors effectively by classifying the sequences of system calls as normal or abnormal. However, an extended intrusion detection mechanism by monitoring multiple processes to detect intrusions that can modify the behaviors of system programs (such as: Trojan Horses, Buffer overflow attacks, and viruses.) is proposed.
机译:在研究过程行为分类的基础上,讨论了一种实用的入侵检测系统原型。作为关键要素之一,系统行为分类器(朴素贝叶斯分类器)可以通过将系统调用序列分类为正常或异常来有效地识别恶意系统行为。但是,提出了一种扩展的入侵检测机制,该机制通过监视多个进程来检测可以修改系统程序行为的入侵(例如:特洛伊木马,缓冲区溢出攻击和病毒)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号