论文部分内容阅读
在现有的单层马尔科夫链异常检测模型基础上,提出一种崭新的两层模型.将性质上有较大差异的两个过程,不同的请求和同一请求内的系统调用序列,分为两层,分别用不同的马尔可夫链来处理.两层结构可以更准确地刻画被保护服务进程的动态行为,因而能较大地提高异常的识别率,降低误警报率.而且异常检测出的异常将被限制在相应的异常真正发生的请求区内.检测模型适合于针对特权进程(特别是基于请求?反应型的特权进程)的异常入侵检测.
Based on the existing single-level Markov chain anomaly detection model, this paper proposes a brand-new two-layer model, which consists of two processes with large differences in nature, different requests and system call sequences in the same request Which are two layers and are respectively treated by different Markov chains.The two-layer structure can describe the dynamic behavior of the service process being protected more accurately, which can greatly improve the recognition rate of anomaly and reduce the false alarm rate.And anomaly detection Will be limited in the corresponding request area where the exception actually occurs.The detection model is suitable for anomaly detection for privileged processes (especially request-response-based privileged processes).