首页    期刊浏览 2024年07月07日 星期日
登录注册

文章基本信息

  • 标题:Automated Approach to Intrusion Detection in VM-based Dynamic Execution Environment
  • 本地全文:下载
  • 作者:Zhao, Feng ; Jin, Hai
  • 期刊名称:COMPUTING AND INFORMATICS
  • 印刷版ISSN:1335-9150
  • 出版年度:2012
  • 卷号:31
  • 期号:2
  • 页码:271-297
  • 语种:English
  • 出版社:COMPUTING AND INFORMATICS
  • 摘要:Because virtual computing platforms are dynamically changing, it is difficult to build high-quality intrusion detection system. In this paper, we present an automated approach to intrusions detection in order to maintain sufficient performance and reduce dependence on execution environment. We discuss a hidden Markov model strategy for abnormality detection using frequent system call sequences, letting us identify attacks and intrusions automatically and efficiently. We also propose an automated mining algorithm, named AGAS, to generate frequent system call sequences. In our approach, the detection performance is adaptively tuned according to the execution state every period. To improve performance, the period value is also under self-adjustment.
  • 关键词:Intrusion detection; virtual machine; hidden Markov model (HMM); sequential data mining; dynamic graph
国家哲学社会科学文献中心版权所有