节点文献

基于两层隐马尔可夫模型的入侵检测方法

Intrusion detection method based on two-layer HMM

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 周星彭勤科王静波

【Author】 ZHOU Xing,PENG Qin-ke,WANG Jing-bo(State Key Laboratory for Manufacturing Systems Engineering,Xi’an Jiaotong University,Xi’an 710049,China)

【机构】 西安交通大学机械制造系统工程国家重点实验室西安交通大学机械制造系统工程国家重点实验室 西安710049西安710049

【摘要】 在基于系统调用的入侵检测研究中,如何提取系统调用序列模式是一个重要问题。提出一种利用进程堆栈中的函数返回地址链信息来提取不定长模式的方法。同王福宏的不定长模式提取方法相比,该方法可以取得更完备的模式集。在此基础上,基于系统调用序列及其对应的不定长模式序列构建了一个两层隐马尔可夫模型来检测异常行为,与仅利用系统调用序列信息的经典隐马尔可夫方法相比,该方法可以取得更低的误报率和漏报率。

【Abstract】 How to extract sequence patterns of system calls is an important research topic of system call based intrusion detection approaches.This paper proposed a new method to construct variable-length patterns by using the chains of function return addresses information from call stack of the process.Compared with Wang’s method,this method could generate a more integrated set of patterns.Then,constructed a two-layer hidden Markov model(HMM) based on variable-length patterns to detect abnormal behaviors.Compared with the traditional HMM method,this method could achieve lower false negatives rate and false positives rate.

【基金】 国家自然科学基金资助项目(60373107)
  • 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2008年03期
  • 【分类号】TP393.08
  • 【被引频次】9
  • 【下载频次】306
节点文献中: 

本文链接的文献网络图示:

本文的引文网络