节点文献

基于访问控制的主机异常入侵检测模型

Access control-based host anomaly intrusion detection model

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 皮建勇巩明树刘心松李泽平

【Author】 PI Jian-yong1,GONG Ming-shu2,LIU Xin-song1,LI Ze-ping1(1.School of Computer Science & Engineering,University of Electronic Science & Technology of China,Chengdu 610054,China;2.61062 Army,The Chinese People’s Liberation Army,Beijing 100091,China)

【机构】 电子科技大学计算机科学与工程学院中国人民解放军61062部队

【摘要】 结合访问控制和入侵检测各自的优势,在以访问控制为系统正常访问参考模式的条件下,提出了基于访问控制的主机异常入侵检测模型——ACB IDS。根据系统调用函数间的约束关系构建基于扩展有向无环图(DAG)的系统调用活动关联图,构建活动关联图的偏离函数,用于计算实际系统调用序列与活动关联图的匹配程度,以达到入侵检测的目的。实验结果表明,ACB IDS相对于传统的入侵检测具有较低的漏报率和误报率,并具有较高的运行效率。

【Abstract】 The model of intrusion detection based on access control(ACBIDS) was proposed under the precondition of positive access reference by access control mechanism,in which combined advantage of access control and intrusion detection respectively.Constructed the activity associate graph based on direct acyclic graph(DAG) according to restriction relations among system call functions,and constructed divergence function about activity associated graph for computing the match degree between actual system call sequence and activity associated graph.The ACBIDS could detect the intrusion action in host finally.The experiment shows this model implements low false positive rate and low false negative rate,and upper efficiency.

【基金】 四川省应用基础研究基金资助项目(04JY029-017-2);科技型中小企业技术创新基金资助项目(04C26225110223)
  • 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2009年02期
  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】166
节点文献中: 

本文链接的文献网络图示:

本文的引文网络