节点文献

基于系统调用与进程堆栈信息的入侵检测方法

Intrusion Detection Based on System Calls and Call Stack Log

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张诚彭勤科

【Author】 ZHANG Cheng,PENG Qinke(School of Electronic and Information Engineering,Xi’an Jiaotong University,Xi’an 710049)

【机构】 西安交通大学电子与信息工程学院西安交通大学电子与信息工程学院 西安710049西安710049

【摘要】 提出一种利用动态提取进程堆栈中的信息来寻找不定长模式的方法。该方法以进程中产生系统调用的函数返回地址链作为提取不定长模式的依据,根据函数的结构关系对模式集进行精简,得到一组不定长模式集。在此基础上,以不定长模式作为基本单位构建了一个马尔可夫链模型来检测异常行为。实验结果表明,该方法的检测性能要优于传统的不定长模式方法和一阶马尔可夫链模型方法,能够获得更高的检测率和更低的误报率。

【Abstract】 A novel method is proposed to construct variable-length patterns by using dynamically extracting information from call stack of the process.This method uses the chains of function return addresses to derive a table of variable-length patterns,and reduces the pattern set based on the structure of functions of the process.Then a Markov chain model is constructed based on variable-length patterns to detect abnormal behaviors.The experimental results indicate that compared with the traditional variable-length pattern based method and the first-order Markov chain model method,the proposed method can achieve higher hit rates and lower false alarm rates.

【基金】 国家自然科学基金资助项目(60373107);国家“863”计划基金资助项目(2003AA142060)
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2007年07期
  • 【分类号】TP393.08
  • 【被引频次】11
  • 【下载频次】140
节点文献中: 

本文链接的文献网络图示:

本文的引文网络