首页> 外文会议>International Conference on Computational Intelligence and Security pt.2 >SoIDPS: Sensor Objects-Based Intrusion Detection and Prevention System and Its Implementation
【24h】

SoIDPS: Sensor Objects-Based Intrusion Detection and Prevention System and Its Implementation

机译:SOIDPS:传感器物体的入侵检测和预防系统及其实施

获取原文

摘要

In this paper, we propose an intrusion detection and prevention system using sensor objects that are a kind of trap and are accessible only by the programs that are allowed by the system. Any access to the sensor object by disallowed programs or any transmission of the sensor object to outside of the system is regarded as an intrusion. In such case, the proposed system logs the related information on the process as well as the network connections, and terminates the suspicious process to prevent any possible intrusion. By implementing the proposed method as Loadable Kernel Module (LKM) in the Linux, it is impossible for any process to access the sensor objects without permission. In addition, the security policy will be dynamically applied at run time. Experimental results show that the security policy is enforced with negligible overhead, compared to the performance of the unmodified original system.
机译:在本文中,我们提出了一种使用传感器对象的入侵检测和预防系统,该系统是一种陷阱,并且只能通过系统允许的程序访问。通过不允许的程序或传感器对象的任何传输到系统外部的任何访问传感器对象被视为入侵。在这种情况下,所提出的系统将相关信息记录在过程中以及网络连接,并终止可疑过程以防止任何可能的入侵。通过在Linux中实现作为可加载的内核模块(LKM)的所提出的方法,任何进程都不可能在未经许可的情况下访问传感器对象。此外,安全策略将在运行时动态应用。实验结果表明,与未修改的原始系统的性能相比,安全策略的开销强制执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号