【24h】

A Formal Framework for Program Anomaly Detection

机译:程序异常检测的正式框架

获取原文

摘要

Program anomaly detection analyzes normal program behaviors and discovers aberrant executions caused by attacks, miscon-figurations, program bugs, and unusual usage patterns. The merit of program anomaly detection is its independence from attack signatures, which enables proactive defense against new and unknown attacks. In this paper, we formalize the general program anomaly detection problem and point out two of its key properties. We present a unified framework to present any program anomaly detection method in terms of its detection capability. We prove the theoretical accuracy limit for program anomaly detection with an abstract detection machine. We show how existing solutions are positioned in our framework and illustrate the gap between state-of-the-art methods and the theoretical accuracy limit. We also point out some potential modeling features for future program anomaly detection evolution.
机译:程序异常检测可分析正常的程序行为,并发现由攻击,配置错误,程序错误和异常使用模式引起的异常执行。程序异常检测的优点是它不受攻击特征的影响,可以主动防御新的和未知的攻击。在本文中,我们对通用程序异常检测问题进行了形式化,并指出了它的两个关键特性。我们提供一个统一的框架,以根据其检测能力来介绍任何程序异常检测方法。我们用抽象检测机证明了程序异常检测的理论精度极限。我们将说明现有解决方案如何定位在我们的框架中,并说明最先进的方法与理论精度极限之间的差距。我们还指出了一些潜在的建模功能,可用于将来程序异常检测的发展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号