Intrusion detection based on system calls and homogeneous Markov chains

来源 :Journal of Systems Engineering and Electronics | 被引量 : 0次 | 上传用户:bambooasu
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
A novel method for detecting anomalous program behavior is presented, which is applicable to host-based intrusion detection systems that monitor system call activities. The method constructs a homogeneous Markov chain model to characterize the normal behavior of a privileged program, and associates the states of the Markov chain with the unique system calls in the training data. At the detection stage, the probabilities that the Markov chain model supports the system call sequences generated by the program are computed. A low probability indicates an anomalous sequence that may result from intrusive activities. Then a decision rule based on the number of anomalous sequences in a locality frame is adopted to classify the program’s behavior. The method gives attention to both computational effciency and detection accuracy, and is especially suitable for on-line detection. It has been applied to practical host-based intrusion detection systems. A novel method for detecting anomalous program behavior is presented, which is applicable to host-based intrusion detection systems that monitor system call activities. The method constructs a homogeneous Markov chain model to characterize the normal behavior of a privileged program, and associates the states of the markov chain with the unique system calls in the training data. At the detection stage, the probabilities that the Markov chain model supports the system call sequences generated by the program are computed. A low probability indicates an anomalous sequence that may result from intrusive activities . The method gives attention to both computational effciency and detection accuracy, and is especially suitable for on-line detection. It has been applied to practical host-based intrusion detection systems.
其他文献
本文以新余钢铁有限责任公司线材厂高速线材生产线为例,简要介绍了德国西门子公司的S7-400 PLC分布式控制系统在新余钢铁有限责任公司线材厂高速线材生产线的开发与应用。
介绍了高碳优质碳素工具钢线材技术条件以及开发高碳工具钢线材存在的问题、攀钢在开发高碳优质碳素工具钢线材过程中所采取的工艺路线、方法以及最终产品情况。
冶金企业的生产特点决定了它在备品备件方面的高消耗,这部分消耗一直都被各个冶金企业列为控制对象。本文介绍了激光处理技术的基本原理、特点及其发展。列举相关实例说明激光
首钢连铸硬线常见质量异议的钢种有45#、70#、80#、SWRH82B系列盘条等,所反映的主要缺陷有夹杂、缩孔、成份偏析、裂纹、网状碳化物、折叠、耳子等,并对这些缺陷产生的原因、解决
运用六西格玛SIPOC图和漏斗原理,从系统出发,结合生产流程,总结提炼出了高线关键工艺参数的选择和分析方法,为优化过程控制,改善流程输出,持续提高线材产品质量提供了借鉴和参考。
通过强化数据分析管理程序在高线厂日常生产中的管理职能工作,形成量化的数据指标评估体系,用以指导现场生产,并提高以指标为标志的技术管理工作,满足生产的需要。
本文介绍了唐钢高线厂关键设备(精轧机)在线监测系统的设计与应用。该系统能够对设备运行状况进行在线监测,实现设备故障的预知、预判,消除设备存在的隐患。
本文通过Gleeble-1500热模拟机对终轧温度和控制冷却过程的模拟,研究终轧温度、吐丝温度及相变区冷却速度对SWRCH22A钢组织的影响。
本文主要阐述了蓄热燃烧技术在应用过程中出现的几个主要问题,并且分析了产生原因,提供了解决方案,对蓄热燃烧技术的应用单位和设计单位具有借鉴的作用。
通过Gleeble-1500热模拟机对终轧温度和控制冷却过程的模拟,研究终轧温度、吐丝温度及相变区冷却速度对SWRCH22A钢相变规律的影响,并测定了该钢种动态连续冷却转变(CCT)曲线。