节点文献

基于系统调用顺序和频度特性的入侵检测模型

A New Intrusion Detection Model Based on Combination of Order and Frequency Characters of System Calls

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张桂玲孙济洲

【Author】 ZHANG Guiling,SUN Jizhou(School of Electronic Information Engineering,Tianjin University,Tianjin 300072)

【机构】 天津大学电信学院天津大学电信学院 天津300072天津300072

【摘要】 提出了一种将系统调用的顺序特性和频度特性相接合来构建入侵检测模型(COFIDS模型)的新方法,该模型采用kNN(k-NearestNeighbor Classifier)算法实现入侵检测,并利用一种改进的相似因子,来增加系统调用序列间相似度的差别,减少了识别误差,提高了检测率,降低了入侵检测的误报率。实验表明,COFIDS还具有较强的抗噪声干扰的能力。

【Abstract】 A new intrusion detection scheme based on the combination of the order and frequency characters of system calls(COFIDS) is proposed.This paper applies a text category algorithm(k-Nearest Neighbor Classifier,kNN) to the proposed intrusion detection scheme.In order to improve the intrusion detection rate,a similarity enhancement factor(SEF) is also presented.The preliminary experimental results demonstrate that the proposed COFIDS can provide obvious improvement in intrusion detection ability.The experiments with COFIDS also show that the proposed scheme has higher ability against to noise in the training data and to intrusion detection false positive rate.

【关键词】 入侵检测系统调用kNN算法
【Key words】 Intrusion detectionSystem callkNN algorithm
【基金】 国家“863”计划基金资助项目(2002AA142010)
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2006年13期
  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】81
节点文献中: 

本文链接的文献网络图示:

本文的引文网络