首页> 外文会议>International Symposium on Networks, Computers and Communications >Using Execution Profiles to Identify Process Behavior Classes
【24h】

Using Execution Profiles to Identify Process Behavior Classes

机译:使用执行配置文件来标识进程行为类

获取原文

摘要

A computer process can exhibit various behaviors (general notion of operations) during its lifetime. Interacting with files, performing computational tasks, and network interactions are example process behaviors. Identifying the current behavior of computer processes can be used to improve resource management and policy enforcement. Inspecting the application instructions (static analysis) can be done to provide a notion of what an application can potentially do; however, certain behaviors may only be exhibited during the actual execution and is dependent on the intended application.This paper investigates a novel dynamic analysis approach that uses execution profiles to identify process behavior. An execution profile is a compact frequency representation of the executed machine instructions associated with an application. For this preliminary work, execution profiles are used in combination with Gaussian Mixture Models (GMMs) to determine if different processes (associated with different applications) cluster together into behavior groups. Experimental results using execution profiles with six different Linux utilities indicate processes cluster based on behavior, unlike static-based analysis.
机译:计算机进程可以在其寿命期间表现出各种行为(操作的一般概念)。与文件进行交互,执行计算任务和网络交互是示例过程行为。识别计算机进程的当前行为可用于改善资源管理和策略实施。检查应用程序指令(静态分析)可以完成,以提供应用程序可能会产生的概念;但是,只有在实际执行期间只能展出某些行为,并且依赖于预期的应用程序。本文调查了一种使用执行配置文件来识别过程行为的新型动态分析方法。执行配置文件是与应用程序相关联的执行的计算机指令的紧凑频率表示。对于此初步工作,执行配置文件与高斯混合模型(GMMS)组合使用,以确定是否将不同的进程(与不同的应用程序相关联)集群一起集聚到行为组中。与静态分析不同,使用具有六种不同的Linux实用程序的执行配置文件的实验结果表明了基于行为的进程集群。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号