首页> 外国专利> Method and apparatus for content-based instrusion detection using an agile kernel-based auditor

Method and apparatus for content-based instrusion detection using an agile kernel-based auditor

机译:使用基于敏捷内核的审计程序进行基于内容的入侵检测的方法和设备

摘要

One embodiment of the present invention provides content-based intrusion detection for a computer system by using an agile kernel-based auditing system. This auditing system operates by receiving an audit specification that specifies target attributes to be recorded during an auditing process. The audit specification also specifies an auditing criterion that triggers recording of the target attributes. Upon receiving the audit specification, the auditing system is configured to record the target attributes during system calls whenever the auditing criterion is satisfied. Next, an application program is monitored by the auditing system to produce an audit log containing the recorded target attributes. This audit log is examined in order to detect patterns for intrusion detection purposes. In one embodiment of the present invention, configuring the auditing system involves compiling the audit specification to produce a kernel module, and then loading the kernel module into a kernel of an operating system. It also involves linking code from within the kernel module into system calls within the operating system. In one embodiment of the present invention, in response to detecting an event during the auditing process, the system dynamically adjusts the auditing system to change the auditing criterion and/or the target attributes for subsequent operation of the auditing system.
机译:本发明的一个实施例通过使用基于敏捷内核的审计系统为计算机系统提供基于内容的入侵检测。该审核系统通过接收审核规范进行操作,该规范指定了在审核过程中要记录的目标属性。审核规范还指定了触发记录目标属性的审核标准。在接收到审核规范后,审核系统配置为每当满足审核标准时在系统调用期间记录目标属性。接下来,审核程序监视应用程序,以生成包含记录的目标属性的审核日志。检查该审核日志,以便检测用于入侵检测目的的模式。在本发明的一个实施例中,配置审核系统包括编译审核规范以产生内核模块,然后将内核模块加载到操作系统的内核中。它还涉及将代码从内核模块内链接到操作系统内的系统调用中。在本发明的一个实施例中,响应于在审计过程期间检测到事件,系统动态地调整审计系统以改变审计准则和/或目标属性,以用于审计系统的后续操作。

著录项

  • 公开/公告号US7024694B1

    专利类型

  • 公开/公告日2006-04-04

    原文格式PDF

  • 申请/专利权人 CHEUK W. KO;

    申请/专利号US20000593280

  • 发明设计人 CHEUK W. KO;

    申请日2000-06-13

  • 分类号G06F11/30;G06F12/14;

  • 国家 US

  • 入库时间 2022-08-21 21:40:41

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号