...
首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Detecting Intrusions through System Call Sequence and Argument Analysis
【24h】

Detecting Intrusions through System Call Sequence and Argument Analysis

机译:通过系统调用序列和参数分析检测入侵

获取原文
获取原文并翻译 | 示例
           

摘要

We describe an unsupervised host-based intrusion detection system based on system call arguments and sequences. We define a set of anomaly detection models for the individual parameters of the call. We then describe a clustering process that helps to better fit models to system call arguments and creates interrelations among different arguments of a system call. Finally, we add a behavioral Markov model in order to capture time correlations and abnormal behaviors. The whole system needs no prior knowledge input; it has a good signal-to-noise ratio, and it is also able to correctly contextualize alarms, giving the user more information to understand whether a true or false positive happened, and to detect global variations over the entire execution flow, as opposed to punctual ones over individual instances.
机译:我们描述了一种基于系统调用参数和序列的无监督的基于主机的入侵检测系统。我们为呼叫的各个参数定义了一组异常检测模型。然后,我们描述了一个群集过程,该过程有助于更好地使模型适合系统调用参数,并在系统调用的不同参数之间创建相互关系。最后,我们添加行为马尔可夫模型,以捕获时间相关性和异常行为。整个系统不需要任何先验知识输入;它具有良好的信噪比,并且还能够正确地使警报上下文相关,从而为用户提供更多信息,以了解发生的是真还是假肯定,并检测整个执行流程中的全局变化,而不是在个别情况下守时。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号