期刊文献+

基于统计语言模型的低耗时入侵检测方法

Low-cost Intrusion Detection Method Based on Statistical Language Models
在线阅读 下载PDF
导出
摘要 针对基于系统调用序列的入侵检测方法在实际应用中成本偏高的问题,在STIDE方法的基础上提出一种低耗时的入侵检测算法。利用N元语义模型分析系统调用序列规律,计算系统调用的贡献度,抽取最能体现用户正常行为的系统调用,建立正常模式库实现异常检测。实验结果证明,该算法在保证检测率不下降的同时,训练和检测系统调用短序列的规模降低70%。 The existing intrusion detection methods based on sequences of system calls have a large overhead to construct normal profile. An efficient algorithm using statistical language models is proposed based on STIDE in order to reduce the computing cost. The system calls which can represent the characteristics of normal behaviors are extracted by an N-gram method. The improved algorithm extracts the most relevant sequences of system calls. Experimental results demonstrate that the computing cost of the improved algorithm has a reduction of 70% than the standard one and no degradation of detecting rate and false positive rate.
出处 《计算机工程》 CAS CSCD 北大核心 2010年第5期10-11,14,共3页 Computer Engineering
关键词 统计语言模型 系统调用 入侵检测 statistical language models system calls intrusion detection
  • 相关文献

参考文献5

  • 1Forrest S, Longstaff T. A Sense of Self for Unix Processes[C]//Proe. of IEEE Symposium on Security and Privacy. [S. 1.]: IEEE Press, 1996: 120-128.
  • 2Hofmeyr S A, Forrest S, Somayaji A. Intrusion Detection Using Sequences of System Calls[J]. Journal of Computer Security, 1998, 6(3): 151.
  • 3Li Yongzhong, Ge Yang, Jing Xu, et al. A New Intrusion Detection Method Based on Fuzzy HMM[C]//Proc. of the 3rd Conference on Industrial Electronics and Applications. [S. 1.]: IEEE Press, 2008: 36.
  • 4Sharma A, Pujari A K, Paliwal K K. Intrusion Detection Using Text Processing Techniques with a Kernel Based Similarity Measure[J]. Computers & Security, 2007, 26(7/8): 488-495.
  • 5Somayaji A, Forrest S. Automated Response Using System-call Delays[C]//Proc. of the 9th Conference on USENIX Security Symposium. Berkeley, CA, USA: [s. n.], 2000: 185-198.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部