CSpace  > 中国科学院计算技术研究所期刊论文  > 英文
Intrusion detection based on system calls and homogeneous Markov chains
Tian Xinguang1,2; Duan Miyi1,2; Sun Chunlai1; Li Wenfa1,2
2008-06-01
发表期刊JOURNAL OF SYSTEMS ENGINEERING AND ELECTRONICS
ISSN1004-4132
卷号19期号:3页码:598-605
摘要A novel method for detecting anomalous program behavior is presented, which is applicable to host-based intrusion detection systems that monitor system call activities. The method constructs a homogeneous Markov chain model to characterize the normal behavior of a privileged program, and associates the states of the Markov chain with the unique system calls in the training data. At the detection stage, the probabilities that the Markov chain model supports the system call sequences generated by the program are computed. A low probability indicates an anomalous sequence that may result from intrusive activities. Then a decision rule based on the number of anomalous sequences in a locality frame is adopted to classify the program's behavior. The method gives attention to both computational efficiency and detection accuracy, and is especially suitable for on-line detection. It has been applied to practical host-based intrusion detection systems.
关键词intrusion detection Markov chain anomaly detection system call
收录类别SCI
语种英语
WOS研究方向Automation & Control Systems ; Engineering ; Operations Research & Management Science
WOS类目Automation & Control Systems ; Engineering, Electrical & Electronic ; Operations Research & Management Science
WOS记录号WOS:000257407900027
出版者SYSTEMS ENGINEERING & ELECTRONICS, EDITORIAL DEPT
引用统计
被引频次:7[WOS]   [WOS记录]     [WOS相关记录]
文献类型期刊论文
条目标识符http://119.78.100.204/handle/2XEOYT63/11119
专题中国科学院计算技术研究所期刊论文_英文
通讯作者Tian Xinguang
作者单位1.Beijing Jiaotong Univ, Inst Comp Technol, Beijing 100029, Peoples R China
2.Chinese Acad Sci, Inst Comp Technol, Beijing 100080, Peoples R China
推荐引用方式
GB/T 7714
Tian Xinguang,Duan Miyi,Sun Chunlai,et al. Intrusion detection based on system calls and homogeneous Markov chains[J]. JOURNAL OF SYSTEMS ENGINEERING AND ELECTRONICS,2008,19(3):598-605.
APA Tian Xinguang,Duan Miyi,Sun Chunlai,&Li Wenfa.(2008).Intrusion detection based on system calls and homogeneous Markov chains.JOURNAL OF SYSTEMS ENGINEERING AND ELECTRONICS,19(3),598-605.
MLA Tian Xinguang,et al."Intrusion detection based on system calls and homogeneous Markov chains".JOURNAL OF SYSTEMS ENGINEERING AND ELECTRONICS 19.3(2008):598-605.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Tian Xinguang]的文章
[Duan Miyi]的文章
[Sun Chunlai]的文章
百度学术
百度学术中相似的文章
[Tian Xinguang]的文章
[Duan Miyi]的文章
[Sun Chunlai]的文章
必应学术
必应学术中相似的文章
[Tian Xinguang]的文章
[Duan Miyi]的文章
[Sun Chunlai]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。