节点文献
基于访问控制的主机异常入侵检测模型
Access control-based host anomaly intrusion detection model
【摘要】 结合访问控制和入侵检测各自的优势,在以访问控制为系统正常访问参考模式的条件下,提出了基于访问控制的主机异常入侵检测模型——ACB IDS。根据系统调用函数间的约束关系构建基于扩展有向无环图(DAG)的系统调用活动关联图,构建活动关联图的偏离函数,用于计算实际系统调用序列与活动关联图的匹配程度,以达到入侵检测的目的。实验结果表明,ACB IDS相对于传统的入侵检测具有较低的漏报率和误报率,并具有较高的运行效率。
【Abstract】 The model of intrusion detection based on access control(ACBIDS) was proposed under the precondition of positive access reference by access control mechanism,in which combined advantage of access control and intrusion detection respectively.Constructed the activity associate graph based on direct acyclic graph(DAG) according to restriction relations among system call functions,and constructed divergence function about activity associated graph for computing the match degree between actual system call sequence and activity associated graph.The ACBIDS could detect the intrusion action in host finally.The experiment shows this model implements low false positive rate and low false negative rate,and upper efficiency.
【Key words】 access control; intrusion detection; ACBIDS; activity associated graph;
- 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2009年02期
- 【分类号】TP393.08
- 【被引频次】8
- 【下载频次】166