作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (06): 129-131. doi: 10.3969/j.issn.1000-3428.2007.06.045

• 安全技术 • 上一篇    下一篇

一种基于行为的主机入侵防护系统设计与实现

李春光,赵 彬,周保群   

  1. (解放军信息工程大学电子技术学院信息安全研究所,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-03-20 发布日期:2007-03-20

Design and Implementation of a Behavior-based Host Intrusion Prevention System

LI Chunguang, ZHAO Bin, ZHOU Baoqun   

  1. (Institute of Information Security, School of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-03-20 Published:2007-03-20

摘要: 提出了一种结合系统调用和过滤器驱动技术的基于行为HIPS,通过在操作系统内核的两个层次上实施强制访问控制,来实时阻止已知和未知攻击的破坏。研究了在Windows2000/XP操作系统中,可应用的安全策略及支持这些策略的实施机制。

关键词: 检测, 访问控制, 主机入侵防护系统

Abstract: This paper presents a behavior-based host intrusion prevention system(HIPS) combined with system call and filter driver technology. By implementing mandatory access control (MAC) in two lays of host operation system kernel, this system can hold back known and unknown attacks. It focuses on the research of applicable security policies and implementation mechanism in Windows2000/XP.

Key words: Detection, Access control, Host intrusion prevention system(HIPS)