Abstract:
This paper presents a behavior-based host intrusion prevention system(HIPS) combined with system call and filter driver technology. By implementing mandatory access control (MAC) in two lays of host operation system kernel, this system can hold back known and unknown attacks. It focuses on the research of applicable security policies and implementation mechanism in Windows2000/XP.
Key words:
Detection,
Access control,
Host intrusion prevention system(HIPS)
摘要: 提出了一种结合系统调用和过滤器驱动技术的基于行为HIPS,通过在操作系统内核的两个层次上实施强制访问控制,来实时阻止已知和未知攻击的破坏。研究了在Windows2000/XP操作系统中,可应用的安全策略及支持这些策略的实施机制。
关键词:
检测,
访问控制,
主机入侵防护系统
LI Chunguang; ZHAO Bin; ZHOU Baoqun. Design and Implementation of a Behavior-based Host Intrusion Prevention System[J]. Computer Engineering, 2007, 33(06): 129-131.
李春光;赵 彬;周保群. 一种基于行为的主机入侵防护系统设计与实现[J]. 计算机工程, 2007, 33(06): 129-131.