首页> 外文会议>International Conference on Hybrid Information Technology >The Architecture of Host-based Intrusion Detection Model Generation System for the Frequency Per System Call
【24h】

The Architecture of Host-based Intrusion Detection Model Generation System for the Frequency Per System Call

机译:基于主机的入侵检测模型生成系统的架构,用于每个系统调用的频率

获取原文

摘要

There have been a number of researches to apply data mining techniques to intrusion detection. However, most of researches have mainly focused on the intrusion detection system in network area and have been done shortly in host area by applying a certain data mining technique to host-based intrusion detection. In this paper, we propose the architecture of host-based intrusion detection model generation system which creates candidate models by various and popular existing data mining techniques and one new technique (sC4.5) for the process behavior data set with the frequency feature per system call and then elects the best appropriate model according to user requirements after evaluating candidate models. The frequency feature per system call is simpler than the existing system call sequence feature in applying to intrusion detection system as the model. We also propose sC4.5 as a decision tree classification algorithm by complimenting existing C4.5 algorithm. sC4.5 preserves classification accuracy like C4.5 and make the decision tree smaller than C4.5.
机译:有许多研究将数据挖掘技术应用于入侵检测。然而,大多数研究主要集中在网络区域中的入侵检测系统上,并且通过将某些数据挖掘技术应用于基于托管的入侵检测,在主机区域内完成。在本文中,我们提出了基于主机的入侵检测模型生成系统的体系结构,其通过各种和流行的现有数据挖掘技术和一个新技术(SC4.5)创建候选模型,以及每个系统的频率特征的过程行为数据集在评估候选模型后,根据用户要求调用并选择最佳合适的模型。每个系统调用的频率特征比应用于模型的入侵检测系统中的现有系统呼叫序列特征更简单。我们还通过赞美现有的C4.5算法提出SC4.5作为决策树分类算法。 SC4.5保留像C4.5等分类准确性,并使决策树小于C4.5。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号