节点文献

基于贝叶斯的Windows注册表访问的异常检测研究

Anomaly Detection Research of Windows Registry Access Bassed on Bayesian

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王斌梁晓诚吴铁峰

【Author】 WANG Bin1,2,LIANG Xiaocheng2,WU Tiefeng1(1.Informaiton Electronic Technology College,Jiamusi University,Jiamusi,154007,China;2.Guilin University of Technology,Guilin,541004,China)

【机构】 佳木斯大学信息电子技术学院桂林工学院佳木斯大学信息电子技术学院 黑龙江佳木斯154007桂林工学院广西桂林541004广西桂林541004黑龙江佳木斯154007

【摘要】 描述了一个针对Windows的基于主机的入侵检测系统。其核心是一个贝叶斯算法,此算法通过寻找异常的对Windows注册表的访问来检测基于主机的攻击,并且评价他的性能。实验结果证明该基于贝叶斯的检测系统在检测恶意行为时是有效的,并能保持较低的误警率,其实验结果表明检测系统具有良好的性能。

【Abstract】 This paper describes a host-based intrusion detection system for Microsoft Windows.The core of the system is a Bayesian classifier that detects attacks on a host machine by looking for anomalous accesses to the Windows registry,and evaluates its performance.The results of experiments shown that the system based on Bayesian classifier described by paper is effective in detecting the actions of malicious software while maintaining a low rate of false alarms.

  • 【文献出处】 现代电子技术 ,Modern Electronics Technique , 编辑部邮箱 ,2007年05期
  • 【分类号】TP316.7
  • 【被引频次】2
  • 【下载频次】96
节点文献中: 

本文链接的文献网络图示:

本文的引文网络