节点文献

进程异常检测中淋巴细胞的逻辑语义模型

A Logic-based Semantic Model of Lymphocytes Applied to Process-based Anomaly Detection

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 关刚董红斌谭成予梁意文

【Author】 Guan Gang Dong Hongbin Tan Chengyu Liang Yiwen (State Key Laboratory of Software Engineering / School of Computer Science, Wuhan University,Wuhan 430072)

【机构】 武汉大学软件工程国家重点实验室/计算机学院武汉大学软件工程国家重点实验室/计算机学院 武汉430072武汉430072武汉430072

【摘要】 论文针对反向选择算法无法有效地捕捉某些复杂问题空间的语义信息的缺点,以逻辑程序设计领域中的稳定模型为理论基础,提出一个淋巴细胞的逻辑语义模型。该模型采用逻辑程序表示淋巴细胞和抗原,通过计算它们的稳定模型来进行异常检测。最后,以进程异常检测为背景,设计了一个系统框架。该框架充分考虑了进程系统调用短序列的语义信息,能有效地提高异常检测的准确率。

【Abstract】 Concerning with the disadvantage that negative selection algorithm can not effectively capture semantic information in some complex problem spaces,this paper proposes a logic-based semantic model of lymphocytes which is based upon stable model theory in logic programming.This model represents lymphocytes and antigens as logic programs and detects abnormal behavior by compute their stable model.Finally,in the background of process-based anomaly detection,the authors have designed a systematic framework which tries to exploit semantic information in subsequences of system call trails generated by processes and is able to effectively improve the accuracy in anomaly detection.

【基金】 国家自然科学重大研究计划项目(编号:90204011);湖北省科技攻关计划课题
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2005年17期
  • 【分类号】TP311.11
  • 【被引频次】2
  • 【下载频次】58
节点文献中: 

本文链接的文献网络图示:

本文的引文网络