首页> 外文OA文献 >Developing a high-accuracy cross platform Host-Based Intrusion Detection System capable of reliably detecting zero-day attacks
【2h】

Developing a high-accuracy cross platform Host-Based Intrusion Detection System capable of reliably detecting zero-day attacks

机译:开发能够可靠地检测零日攻击的高精度跨平台基于主机的入侵检测系统

摘要

Current anomaly host-based intrusion detection systems are limited in accuracy with any increase in detection rate resulting in a corresponding increase in false alarm rate. Furthermore, present technology is largely limited in scope to the Linux operating system, with the popular Windows family of computers forced to rely on signature-based protection schemes.This thesis investigates the development of a new approach to host-based intrusion detection system design with the specific aims of improving performance beyond that of existing technology and developing a cross platform approach to intrusion detection. This research has made three original and significant contributions to the field, and represents a marked advance in the body of knowledge.The first major contribution is the development of a new semantic approach to system call data processing, allowing the creation of host-based intrusion detection systems for the Linux operating system which perform significantly better than existing approaches. Performance was evaluated against existing datasets and also against a new modern dataset designed as part of this research. The second key contribution is the development of a new theory which allows the deployment of traditional system call centric Linux anomaly-based intrusion detection systems on the Windows operating system for the first time. This significant technological advance means that protection against zero-day attacks is now possible on this operating system for the first time. These results were tested using a second new dataset designed as part of this research.The final key contribution of this thesis is the development of a new attack methodology which is able to bypass traditional Windows signature-based defences without any obfuscation. The revelation of this new attack technology is an important contribution in and of itself as it allows the community of researchers worldwide to address this important weakness in current approaches. Notwithstanding this threat, host-based intrusion detection systems which use the first two new theories outlined in this thesis are shown to be able to detect this new attack class with a high degree of accuracy, allowing effective protection and significantly mitigating this threat.
机译:当前的基于异常主机的入侵检测系统的准确性受到限制,检测率的任何提高都会导致虚警率的相应提高。此外,目前的技术在很大程度上限于Linux操作系统,流行的Windows计算机家族被迫依赖基于签名的保护方案。本文研究了一种新的基于主机的入侵检测系统设计方法的开发。其特定目标是提高性能,使其超越现有技术,并开发一种跨平台的入侵检测方法。这项研究为该领域做出了三项原始且重要的贡献,代表了知识体系的显着进步。第一个主要贡献是开发了一种用于系统调用数据处理的新语义方法,从而允许创建基于主机的入侵用于Linux操作系统的检测系统,其性能明显优于现有方法。针对现有数据集以及作为本研究一部分而设计的新的现代数据集对性能进行了评估。第二个主要贡献是新理论的发展,该理论首次允许在Windows操作系统上部署传统的以系统调用为中心的基于Linux异常的入侵检测系统。这项重大的技术进步意味着,现在首次可以在此操作系统上防御零日攻击。这些结果是使用作为本研究的一部分设计的第二个新数据集进行测试的。本文的最后主要贡献是开发了一种新的攻击方法,该方法能够绕过传统的基于Windows签名的防御而不会产生任何混淆。这项新攻击技术的发现本身就是一项重要的贡献,因为它使全世界的研究人员社区能够解决当前方法中的这一重要弱点。尽管存在这种威胁,但使用本文概述的前两个新理论的基于主机的入侵检测系统被证明能够高度准确地检测到这种新的攻击类别,从而可以提供有效的保护并显着缓解这种威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号