首页 | 本学科首页   官方微博 | 高级检索  
     

基于Windows Native API序列的系统行为入侵检测
引用本文:朱莺嘤,叶茂,刘乃琦,李筝,郑凯元. 基于Windows Native API序列的系统行为入侵检测[J]. 计算机工程与应用, 2008, 44(18): 109-112. DOI: 10.3778/j.issn.1002-8331.2008.18.034
作者姓名:朱莺嘤  叶茂  刘乃琦  李筝  郑凯元
作者单位:电子科技大学计算机学院,成都,610054;电子科技大学通信学院,成都,610054
基金项目:国家自然科学基金 , 教育部跨世纪优秀人才培养计划 , 四川省自然科学基金
摘    要:针对Windows系统入侵检测的不足,研究并借鉴Linux下基于系统调用序列进行入侵检测的方法,提出一种采用BP神经网络算法对Windows Native API序列学习和分类的内核级主机入侵检测方案。通过实验,验证了采用Windows Native API序列进行系统入侵的可行性。Native API是Windows系统内核模式下的API,可以类比于Linux下的系统调用。通过训练神经网络学习Native API序列,建立一个对正常和异常Native API序列进行分类的BP神经网络。在入侵检测时,利用训练后的神经网络对不断出现的Windows Native API 序列进行分类,判断系统是否出现异常入侵。

关 键 词:入侵检测  Windows’Native’API  BP神经网络
文章编号:1002-8331(2008)18-0109-04
收稿时间:2007-09-19
修稿时间:2007-09-19

Host intrusion detection based on sequence of Windows Native API
ZHU Ying-ying,YE Mao,LIU Nai-qi,LI Zheng,ZHENG Kai-yuan. Host intrusion detection based on sequence of Windows Native API[J]. Computer Engineering and Applications, 2008, 44(18): 109-112. DOI: 10.3778/j.issn.1002-8331.2008.18.034
Authors:ZHU Ying-ying  YE Mao  LIU Nai-qi  LI Zheng  ZHENG Kai-yuan
Affiliation:1.College of Computer,University of Electronic Science and Technology of China,Chengdu 610054,China 2.College of Communication and Inf. Eng.,University of Electronic Science and Technology of China,Chengdu 610054,China
Abstract:Considering the shortcomings of Windows system intrusion detection and the advantages of the Linux system intrusion detection based on the sequence of the system call,a kernel-level host intrusion detection program based on the BP neural network algorithm to study and classify the sequence of Windows Native API is proposed in this paper.Experiment results prove that the sequence of Native API can be used for intrusion detection.Windows Native API means the kernel model API,which is similar to the Linux system call.The neural network is trained to learn the normal and abnormal sequence of Native API.In the intrusion detection,use the trained neural network to classify the emerging Native API sequence,and find whether the intrusion happens.
Keywords:intrusion detection  Windows Native API  BP neural network
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号