节点文献
基于系统调用的异常入侵检测研究
Anomaly Detection Research Based on System Calls
【摘要】 基于时序、频率等特性,系统调用序列已成为基于主机的入侵检测系统重要的数据源之一。通过分析系统调用序列来判断入侵事件,具有准确性高、误警率低和稳定性好等优点,目前,国际上在这方面的研究主要集中在如何设计有效的检测算法以提高检测效果。该文对目前国际上基于系统调用的异常入侵检测方面的研究进展进行了总结,对主要的检测技术进行了详细讨论和分析。
【Abstract】 System calls have already became an important data source of hosts-based intrusion detection system based on its sequential and frequency characteristics.The method whether an event is intrusion through analyzing system calls,has the virtues of high accuracy,low false fault and good stability and so on.At present ,the international research mainly focuses on how to design effective detection algorithms for improving detective effect.This paper summarizes the research progress of anomaly detection based on system calls,discusses and analyzes its main detection technology in detail.
【Key words】 system call; anomaly intrusion detection; time characteristic; frequency characteristic;
- 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2004年17期
- 【分类号】TP393.08
- 【被引频次】12
- 【下载频次】166