节点文献
基于恶意代码行为分析的入侵检测技术研究
Intrusion Detection Based on Malicious Code Behavior Analysis
【摘要】 在进行入侵检测的过程中,传统方法由于对入侵判断过程的约束性过强,同时入侵数据中存在大量的冗余数据与噪声,导致无法抵御行为层混淆干扰造成的检测精确性过低的问题,不能从网络安全立体、纵深、多层次防御的角度出发对网络入侵进行检测。为此,提出了一种基于半监督聚类算法的恶意代码行为分析的入侵检测方法。提取系统调用流图特征,将其融合于代码的行为结构与特征中,标记后按照类型将其归纳整理,将整理后带有标记的代码行为特性数据的信息范围扩展到所在簇内的全部数据上,实现类型标记,完成对恶意代码行为的分析,实现入侵检测。仿真结果表明,提出的基于半监督聚类算法的恶意代码行为分析的入侵检测方法精准度高,实用性强。
【Abstract】 This paper proposes an intrusion detection method based on behavior analysis of malicious codes via the semi- supervised clustering algorithm. The features of system call flow graph are extracted to integrate in the behavior of the code structure and features,and marked to make induction and reorganization according to their types.The code behavior characteristics data with mark are extended to all of the data within a cluster after organizing,then the type mark is implemented,the analysis of malicious code behavior is completed,and the intrusion detection is realized. Simulation results show that the proposed intrusion detection method has high precision and strong practicability.
【Key words】 Intrusion detection; Semi-supervised clustering; Malicious code;
- 【文献出处】 计算机仿真 ,Computer Simulation , 编辑部邮箱 ,2015年04期
- 【分类号】TP393.08
- 【被引频次】12
- 【下载频次】235