节点文献
基于两层隐马尔可夫模型的入侵检测方法
Intrusion detection method based on two-layer HMM
【摘要】 在基于系统调用的入侵检测研究中,如何提取系统调用序列模式是一个重要问题。提出一种利用进程堆栈中的函数返回地址链信息来提取不定长模式的方法。同王福宏的不定长模式提取方法相比,该方法可以取得更完备的模式集。在此基础上,基于系统调用序列及其对应的不定长模式序列构建了一个两层隐马尔可夫模型来检测异常行为,与仅利用系统调用序列信息的经典隐马尔可夫方法相比,该方法可以取得更低的误报率和漏报率。
【Abstract】 How to extract sequence patterns of system calls is an important research topic of system call based intrusion detection approaches.This paper proposed a new method to construct variable-length patterns by using the chains of function return addresses information from call stack of the process.Compared with Wang’s method,this method could generate a more integrated set of patterns.Then,constructed a two-layer hidden Markov model(HMM) based on variable-length patterns to detect abnormal behaviors.Compared with the traditional HMM method,this method could achieve lower false negatives rate and false positives rate.
【Key words】 intrusion detection; system call; process stack; function return address; variable-length patterns; two-layer hidden Markov model;
- 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2008年03期
- 【分类号】TP393.08
- 【被引频次】9
- 【下载频次】306