首页> 外国专利> Automatically generating valid behavior specifications for intrusion detection

Automatically generating valid behavior specifications for intrusion detection

机译:自动生成有效的行为规范以进行入侵检测

摘要

One embodiment of the present invention provides a system that automatically generates a valid behavior specification for use in an intrusion detection system for a computer system. The system operates by receiving an exemplary set of system calls that includes positive examples of valid system calls, and possibly negative examples of invalid system calls. The system automatically constructs the valid behavior specification from the exemplary set of system calls by selecting a set of rules covering valid system calls. This set of rules is selected to cover all positive examples in the exemplary set of system calls without covering negative examples. Moreover, the process of selecting a rule for the valid behavior specification involves using an objective function that seeks to maximize the number of positive examples covered by the rule while seeking to minimize the number of possible system calls covered by the rule. In one embodiment of the present invention, the system additionally monitors an executing program. During this monitoring process, the system receives a system call generated by the executing program. The system next determines whether the system call is covered by a rule from within the valid behavior specification. If not, the system generates and indication that the system call is invalid.
机译:本发明的一个实施例提供了一种系统,该系统自动生成用于计算机系统的入侵检测系统中的有效行为规范。该系统通过接收示例性的一组系统调用进行操作,该组系统调用包括有效系统调用的肯定示例,以及无效系统调用的可能否定示例。系统通过选择覆盖有效系统调用的一组规则,从示例性系统调用集自动构建有效行为规范。选择该组规则以覆盖示例性系统调用集中的所有肯定示例,而不包括否定示例。此外,为有效行为规范选择规则的过程涉及使用目标函数,该函数寻求最大化规则覆盖的肯定示例的数量,同时寻求最小化规则覆盖的可能系统调用的数量。在本发明的一个实施例中,系统另外监视执行程序。在此监视过程中,系统会接收执行程序生成的系统调用。接下来,系统从有效行为规范内确定规则是否覆盖系统调用。如果不是,则系统生成并指示系统调用无效。

著录项

  • 公开/公告号US6983380B2

    专利类型

  • 公开/公告日2006-01-03

    原文格式PDF

  • 申请/专利权人 CHEUK W. KO;

    申请/专利号US20010778623

  • 发明设计人 CHEUK W. KO;

    申请日2001-02-06

  • 分类号G06F11/30;G06F12/14;H04L9/00;H04L9/32;

  • 国家 US

  • 入库时间 2022-08-21 21:40:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号