首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Layered Security Architecture for Masquerade Attack Detection
【24h】

Layered Security Architecture for Masquerade Attack Detection

机译:用于伪装攻击检测的分层安全体系结构

获取原文

摘要

Masquerade attack refers to an attack that uses a fake identity, to gain unauthorized access to personal computer information through legitimate access identification. Automatic discovery of masqueraders is sometimes undertaken by detecting significant departures from normal user behavior. If a user's normal profile deviates from their original behavior, it could potentially signal an ongoing masquerade attack. In this paper we proposed a new framework to capture data in a comprehensive manner by collecting data in different layers across multiple applications. Our approach generates feature vectors which contain the output gained from analysis across multiple layers such as Window Data, Mouse Data, Keyboard Data, Command Line Data, File Access Data and Authentication Data. We evaluated our approach by several experiments with a significant number of participants. Our experimental results show better detection rates with acceptable false positives which none of the earlier approaches has achieved this level of accuracy so far.
机译:假面舞会攻击是指使用伪造身份通过合法访问标识未经授权访问个人计算机信息的攻击。伪装者的自动发现有时是通过检测与正常用户行为的重大偏离来进行的。如果用户的正常个人资料偏离了其原始行为,则可能表示正在进行化妆舞会。在本文中,我们提出了一个新的框架,该框架通过在多个应用程序的不同层中收集数据来以全面的方式捕获数据。我们的方法生成特征向量,其中包含从多层分析获得的输出,例如窗口数据,鼠标数据,键盘数据,命令行数据,文件访问数据和身份验证数据。我们通过大量参与者的几次实验评估了我们的方法。我们的实验结果显示出更好的检测率和可接受的误报率,迄今为止,迄今为止,尚无任何一种方法能达到这种准确度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号