节点文献

确定性退火算法在“伪装”入侵行为检测中的应用

Detecting Masquerades in Intrusion Detection Based on Deterministic Annealing

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 赵俊忠黄厚宽田盛丰

【Author】 ZHAO Jun zhong 1,HUANG Hou kuan 2,TIAN Sheng feng 2 (1 School of Science,Beijing University of Aeronautics and astronautics,Beijing 100083,China; 2 School of Computer and Information Technology,Northern Jiaotong University,Beijing 100044,China)

【机构】 北京航空航天大学理学院北方交通大学计算机与信息技术学院北方交通大学计算机与信息技术学院 北京100083北京100044北京100044

【摘要】 本文提出了一种基于确定性退火算法的检测“伪装”入侵行为的方法 .在该方法中 ,每一个用户被看作是一个离散变长记忆的平稳信源 ,被“伪装”的入侵者利用的账户所产生的命令行字符序列可以被看作是由该账户的相应用户和“伪装”的入侵者两个不同信源在不同时段活动的混合结果 .我们通过对命令行字符序列的分析来重构原信源模型以判断是否存在入侵行为 .实验结果表明该模型是可行的

【Abstract】 A new model based on deterministic annealing for detecting intruders/users masquerading as other users is presented.In our model,each user is viewed as a discrete stationary source with variable memory.A sequence of characters composed of command lines from a user’s account is regarded as the result that is potentially generated by the user and the intruder in different period.We determine masquerades by finding the source(s) in the sequence.Our experiment shows that the model is feasible.

  • 【文献出处】 电子学报 ,Acta Electronica Sinica , 编辑部邮箱 ,2004年02期
  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】139
节点文献中: 

本文链接的文献网络图示:

本文的引文网络