一种分析系统调用序列的入侵检测系统设计与实现

Design and Implementation of an Intrusion Detection System Using System Call Serial Analysis

  • 摘要: 结合程序局部性原理,提出系统调用序列中位置间的相关度定义.利用相关度给出了实际系统调用序列与正常系统调用序列间的模糊匹配方法,利用该方法判断应用程序运行状况,进行入侵检测.给出了一个采用该方法的主机入侵检测系统,说明了其整体结构设计、模块间调用关系、模块设计原理、模块实现方法及用于验证该入侵检测系统的实验环境.通过实验结果验证了检测方法是有效的.

     

    Abstract: Correlation between system calls at different positions is defined based on local theory of programming. A fuzzy matching method, which works between the real system call serial and normal system call serial is presented, using the correlation defined. This method can be used to judge whether the program is running normally and therefore used for intrusion detection. A host based intrusion detection system using the method described above is presented and its system structure, as well as the relation among modules, principle and design of the module are given in detail. A test-bed was used to test the intrusion detection system and the test results used to show the validity of the method.

     

/

返回文章
返回
Baidu
map