Research on the security audit model in intrusion prevention based on write-related support vector data description
|更新时间:2024-10-14
|
Research on the security audit model in intrusion prevention based on write-related support vector data description
Issue 7, Pages: 8-14(2007)
作者机构:
1. 解放军理工大学指挥自动化学院
2. 解放军理工大学指挥自动化学院,江苏,南京,210007
作者简介:
基金信息:
DOI:
CLC:TP393.08
Published:2007
稿件说明:
移动端阅览
LUO Jun, PAN Zhi-song, MIAO Zhi-min, et al. Research on the security audit model in intrusion prevention based on write-related support vector data description[J]. 2007, (7): 8-14.
DOI:
LUO Jun, PAN Zhi-song, MIAO Zhi-min, et al. Research on the security audit model in intrusion prevention based on write-related support vector data description[J]. 2007, (7): 8-14.DOI:
Research on the security audit model in intrusion prevention based on write-related support vector data description
摘要
设计了基于写相关支持向量描述的安全审计模型来实现一个新的单类分类器
对系统调用中"写性质"子集进行监视和分析
并以此训练单类分类器
使偏离正常模式的活动都被认为是潜在的入侵。该模型仅利用正常样本建立了单分类器
因此系统还具有对新的异常行为进行检测的能力。通过对主机系统执行迹国际标准数据集的优化处理
只利用少量的训练样本
实验获得了对异常样本100%的检测率
而平均虚警率接近为0。
Abstract
The security audit model based on write-related SVDD was designed to resolve the one-class problem.Once the classifier has been trained using the write-related subset
all activities deviated from the normal patterns are classified as potential intrusion.The proposed one-class classification algorithms can be implemented to build up an anomaly detection system by using only normal samples and the algorithms also makes the security audit system detect the new anomaly behaviors.In the experiments
the One-class classifier acquires nearly 100% detection rate and average zero false alarm rate for sequences of system calls based on a small training dataset.