计算机工程 ›› 2008, Vol. 34 ›› Issue (24): 155-156.doi: 10.3969/j.issn.1000-3428.2008.24.053

• 安全技术 • 上一篇    下一篇

基于特征模式的马尔可夫链异常检测模型

孙美凤,黄 飞,陈云菁,殷新春   

  1. (扬州大学信息工程学院,扬州 225009)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-12-20 发布日期:2008-12-20

Markov Chain Anomaly Detection Model Based on Characteristic Patterns

SUN Mei-feng, HUANG Fei, CHEN Yun-jing, YIN Xin-chun   

  1. (Information and Engineering College, Yangzhou University, Yangzhou 225009)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-12-20 Published:2008-12-20

摘要: 为提高检测精度,同时保持算法复杂度在可接受范围内,提出基于特征模式的马尔可夫链异常检测模型。提取所有支持度大于阈值的系统调用短序列为特征模式,在此基础上建立改进的马尔可夫模型CPMC。在检测时,用程序轨迹匹配特征模式,计算其在CPMC模型下的概率,概率小则代表异常。实验表明,该方法的检测精度高于目前常见的几种单一方法,与DBCPIDS方法的精度近似相等,但其计算复杂度更低。

关键词: 特征模式, 系统调用, 马尔可夫模型

Abstract: In order to improve the accuracy and maintain an acceptable algorithm complexity, this paper proposes a new method for anomaly detection based on characteristic patterns and Markov chain model. It extracts the short sequence of system calls as a characteristic pattern if this sequence satisfies the certain support degree, and proposes an improved Markov model CPMC on this basis. When detecting intrusions, it uses the program trace to match characteristic patterns, and calculates the trace’s probability under CPMC model. Small probability means anomaly. Experimental results show that higher detection accuracy can be got than that with other current single methods. Compared with DBCPIDS, the method has the approximate accuracy but lower computational complexity.

Key words: characteristic patterns, system call, Markov model

中图分类号: