节点文献
进程异常检测中淋巴细胞的逻辑语义模型
A Logic-based Semantic Model of Lymphocytes Applied to Process-based Anomaly Detection
【摘要】 论文针对反向选择算法无法有效地捕捉某些复杂问题空间的语义信息的缺点,以逻辑程序设计领域中的稳定模型为理论基础,提出一个淋巴细胞的逻辑语义模型。该模型采用逻辑程序表示淋巴细胞和抗原,通过计算它们的稳定模型来进行异常检测。最后,以进程异常检测为背景,设计了一个系统框架。该框架充分考虑了进程系统调用短序列的语义信息,能有效地提高异常检测的准确率。
【Abstract】 Concerning with the disadvantage that negative selection algorithm can not effectively capture semantic information in some complex problem spaces,this paper proposes a logic-based semantic model of lymphocytes which is based upon stable model theory in logic programming.This model represents lymphocytes and antigens as logic programs and detects abnormal behavior by compute their stable model.Finally,in the background of process-based anomaly detection,the authors have designed a systematic framework which tries to exploit semantic information in subsequences of system call trails generated by processes and is able to effectively improve the accuracy in anomaly detection.
- 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2005年17期
- 【分类号】TP311.11
- 【被引频次】2
- 【下载频次】58