作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (10): 132-134.

• 安全技术 • 上一篇    下一篇

一种 Windows 主机入侵检测实验系统

王 勇 1,2,章熙骏3,杨辉华1,2,王行愚2   

  1. 1. 桂林电子工业学院网络信息中心,桂林 541004;2. 华东理工大学信息科学与工程学院,上海 200237;3. 桂林市发展与改革委员会,桂林 541001
  • 出版日期:2006-05-20 发布日期:2006-05-20

Windows Host Intrusion Detection Experimental System

WANG Yong1,2, ZHANG Xijun3, YANG Huihua1,2, WANG Xingyu2   

  1. 1. Network Information Center, Guilin University of Electronic Technology, Guilin 541004; 2. College of Information Science and Engineering,East China University of Science & Technology, Shanghai 200237; 3. Guilin Reform and Development Committee, Guilin 541001
  • Online:2006-05-20 Published:2006-05-20

摘要: 针对广泛使用的Windows 平台,建立了一个基于主机的入侵检测实验系统。在深入分析Windows 主机的安全特性的基础上,利用安全日志、系统日志、性能日志及文件完整性校验、注册表等多种信息,提出了18 项入侵检测特征,并利用支持向量机建立入侵检测器,实现了对多种攻击的检测。实验结果表明,特征选取合理、检测方法有效。

关键词: 入侵检测系统;异常检测;Windows 主机;特征选取;支持向量机

Abstract: A kind of intrusion detection experimental system on the widely used Windows platform is put forward. On the basis of a thorough analysis of Windows’ security properties, 18 variables are suggested to be extracted as intrusion features from Windows’ security log, system log, performance log, file integrity check, the changes of registry keys et al, and then support vector machines are used as intrusion detector to find out all sorts of intrusions. The experiment results demonstrate that the extracted features are reasonable selected and the detection method is effective

Key words: Intrusion detection system; Anomaly detection; Windows host; Feature selection; Support vector machines