首页> 外文会议>International Conference on Computer Science and Software Engineering >Robust Host Anomaly Detector Using Strong Isolation
【24h】

Robust Host Anomaly Detector Using Strong Isolation

机译:强大的宿主异常探测器使用强孤立

获取原文

摘要

Current operating systems become greater and complex increasingly and a great lot of vulnerabilities and hidden risks are in existence. Host-based intrusion detector is subject to attack relative to network-based intrusion detection because operating systems provide poor isolation. An alterative architecture and method used for host anomaly detector are proposed by making use of the SKAS mode of User Mode Linux Virtual Machine Monitor to enhance the survivability and robustness of anomaly detector on system calls. Even if attackers have gained unauthorized access to system services it is impossible for them to gain access chance to the anomaly detector because of strong space isolation. The primary experiments show that robustness, survivability and anomaly discriminating capability of host-based intrusion detector are improved.
机译:目前的操作系统越来越多地变得越来越复杂,并且存在大量漏洞和隐藏的风险。基于宿主的入侵探测器可能相对于基于网络的入侵检测攻击,因为操作系统提供了不良隔离。通过利用Linux虚拟机监视器的SKAS模式,提出了一种用于主机异常检测器的替代架构和方法,提高了系统调用上异常检测器的生存能力和鲁棒性。即使攻击者已经获得未经授权的系统服务访问,它们也无法因为空间隔离而获得对异常探测器的访问机会。主要实验表明,基于宿主的入侵探测器的鲁棒性,生存能力和异常区分能力得到改善。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号