详细信息
文献类型:期刊文献
中文题名:一种Windows主机入侵检测实验系统
英文题名:Windows Host Intrusion Detection Experimental System
作者:王勇[1,2];章熙骏[3];杨辉华[1,2];王行愚[4]
机构:[1]桂林电子工业学院网络信息中心;[2]华东理工大学信息科学与工程学院,上海200237;[3]桂林市发展与改革委员会;[4]华东理工大学信息科学与工程学院
年份:2006
卷号:32
期号:10
起止页码:132
中文期刊名:计算机工程
外文期刊名:Computer Engineering
收录:CSTPCD;;EI(收录号:2006249938903);Scopus;北大核心:【北大核心2004】;CSCD:【CSCD2011_2012】;
基金:国家重点基础研究发展规划基金资助项目(2002CB312200);教育部高校博士点基金资助项目(20040251010);广西自然科学基金资助项目(桂科基0575094)
语种:中文
中文关键词:入侵检测系统;异常检测;Windows主机;特征选取;支持向量机
外文关键词:Intrusion detection system; Anomaly detection; Windows host; Feature selection; Support vector machines
摘要:针对广泛使用的Windows平台,建立了一个基于主机的入侵检测实验系统。在深入分析Windows主机的安全特性的基础上,利用安全日志、系统日志、性能日志及文件完整性校验、注册表等多种信息,提出了18项入侵检测特征,并利用支持向量机建立入侵检测器,实现了对多种攻击的检测。实验结果表明,特征选取合理、检测方法有效。
A kind of intrusion detection experimental system on the widely used Windows platform is put forward. On the basis of a thorough analysis of Windows' security properties, 18 variables are suggested to be extracted as intrusion features from Windows' security log, system log, performance log, file integrity check, the changes of registry keys et al, and then support vector machines are used as intrusion detector to find out all sorts of intrusions. The experiment results demonstrate that the extracted features are reasonable selected and the detection method is effective.
参考文献:
正在载入数据...
