首页> 外文会议>International Conference on Computer and Network Technology >A Kernel level VFS logger for building efficient file system Intrusion Detection System
【24h】

A Kernel level VFS logger for building efficient file system Intrusion Detection System

机译:用于构建高效文件系统入侵检测系统的内核级VFS记录器

获取原文

摘要

For any file, the modification, access and creation date and time stamp (MAC DTS) is a major parameter, which if preserved properly can be used to gain crucial evidence about activities on the file. Activities on a file system is generally protected by access control mechanism specific to the operating system; discretionary or mandatory access control mechanism being the most common ones. Generally, access control mechanisms deal with allow or deny a based rule (for access to a file) which even extends to role based access control in some cases. This directly implies that access protection mechanism is generally tightly coupled with almost all operating systems. Still, intrusion is a common phenomenon. This paper analyzes and measures the performance of our previously defined approach for efficient file system intrusion detection system. This paper also establishes how this approach can be complementary to existing access control mechanism for Linux kernel 2.6.x.
机译:对于任何文件,修改,访问和创建日期和时间戳(MAC DTS)是一个主要参数,如果保留正确,可用于获得关于文件活动的关键证据。 文件系统上的活动通常受到特定于操作系统的访问控制机制的保护; 自由裁量或强制性访问控制机制是最常见的机制。 通常,访问控制机制处理允许或拒绝基于的规则(用于访问文件),其甚至在某些情况下扩展到基于角色的访问控制。 这直接意味着访问保护机制通常与几乎所有操作系统紧密耦合。 尽管如此,侵入是一种常见的现象。 本文分析和测量我们先前定义了高效文件系统入侵检测系统的方法的性能。 本文还建立了如何对Linux内核的现有访问控制机制互补的方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号