作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (02): 120-121. doi: 10.3969/j.issn.1000-3428.2007.02.041

• 安全技术 • 上一篇    下一篇

基于系统调用的异常入侵检测

李红娇,李建华,诸鸿文   

  1. (上海交通大学电子工程系,上海 200030)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-01-20 发布日期:2007-01-20

Anomaly Intrusion Detection Based on System Call

LI Hongjiao, LI Jianhua, ZHU Hongwen   

  1. (Department of Electronic Engineering, Shanghai Jiaotong University, Shanghai 200030)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-01-20 Published:2007-01-20

摘要: 监视程序行为是近年基于主机的异常入侵检测的研究热点,构建程序行为模型是进行异常检测的关键。该文根据构建程序行为模型时,从系统调用抽取的信息和异常检测中使用的系统调用序列的粒度以及异常检测器记录的信息,分析和比较了基于程序行为的异常检测技术,并对该项研究作了展望。

关键词: 基于主机的异常检测, 系统调用序列, 控制流

Abstract: Monitoring program behavior is one of the highlighted research topics of host-based anomaly detection recently. The key is to construct a program behavior-based anomaly detection model. Some existing anomaly detection techniques based on system call sequences are analyzed and discussed in this paper. They are compared from three dimensions: the information extracted from system call, the system call level used in anomaly detection and the information recorded by anomaly detector. Future work in this direction is also presented.

Key words: Host-based anomaly detection, System call sequence, Control flow