节点文献
基于贝叶斯的Windows注册表访问的异常检测研究
Anomaly Detection Research of Windows Registry Access Bassed on Bayesian
【摘要】 描述了一个针对Windows的基于主机的入侵检测系统。其核心是一个贝叶斯算法,此算法通过寻找异常的对Windows注册表的访问来检测基于主机的攻击,并且评价他的性能。实验结果证明该基于贝叶斯的检测系统在检测恶意行为时是有效的,并能保持较低的误警率,其实验结果表明检测系统具有良好的性能。
【Abstract】 This paper describes a host-based intrusion detection system for Microsoft Windows.The core of the system is a Bayesian classifier that detects attacks on a host machine by looking for anomalous accesses to the Windows registry,and evaluates its performance.The results of experiments shown that the system based on Bayesian classifier described by paper is effective in detecting the actions of malicious software while maintaining a low rate of false alarms.
【关键词】 异常检测;
注册表访问;
贝叶斯算法;
入侵检测系统;
【Key words】 anomaly detection; registry access; Bayesian algorithm; intrusion detection;
【Key words】 anomaly detection; registry access; Bayesian algorithm; intrusion detection;
- 【文献出处】 现代电子技术 ,Modern Electronics Technique , 编辑部邮箱 ,2007年05期
- 【分类号】TP316.7
- 【被引频次】2
- 【下载频次】96