首页 | 本学科首页   官方微博 | 高级检索  
     

基于满十六叉有序树的程序行为建模搜索方法
引用本文:骆玉霞,刘金刚. 基于满十六叉有序树的程序行为建模搜索方法[J]. 计算机工程与科学, 2007, 29(6): 4-6
作者姓名:骆玉霞  刘金刚
作者单位:中国科学院计算技术研究所,北京,100080;中国科学院研究生院,北京,100039;中国科学院计算技术研究所,北京,100080;首都师范大学计算机科学联合研究院,北京,100037
摘    要:程序行为建模及搜索是异常检测研究中的关键问题。本文提出利用系统调用发生时的程序计数器值对应的段号和段内偏移作为事件,将滑动窗口在有序事件上滑动得到事件序列集合,利用满十六叉有序树算法建立正常行为模型库。满十六叉有序树是为提高规则库的存储及搜索的效率而设计的,其存储的字节顺序隐含着结点间关系信息。在规则库中搜索某条规则的时间复杂度仅与树的深度有关,树的深度固定时的时间复杂度为O(1)。文中给出了满十六叉有序树的定义,分析了它的特点,并给出生成算法和搜索算法。

关 键 词:正常程序行为模型库  事件  满十六叉有序树  异常检测
文章编号:1007-130X(2007)06-0004-03
修稿时间:2006-10-102006-12-15

A Method for Program Behavior Modeling and Searching Based on Full 16-ary Ordered Trees
LUO Yu-xia,LIU Jin-gang. A Method for Program Behavior Modeling and Searching Based on Full 16-ary Ordered Trees[J]. Computer Engineering & Science, 2007, 29(6): 4-6
Authors:LUO Yu-xia  LIU Jin-gang
Affiliation:1. Institute of Computing Technology,Chinese Academy of Sciences, Beijing 100080; 2. Joint Faculty of Computer Science,Capital Normal University, Beijing 100037; 3. Graduate School, Chinese Academy of Sciences, Beijing 100039, China
Abstract:Program behavior modeling and searching is the key issue of anomaly detection. A method is presented, in which the segment ID and the offset of the program counter (PC),when system calls are invoked,are used as events.The event sequence set is produced by sliding the window in orderly events, and a normal behavior model set is built by using full 16-ary ordered trees.A full 16-ary ordered tree is designed for improving the efficiency of storing and searching rule sets.The storage byte sequence in the full 16-ary ordered tree implies the relationship information between nodes. The time complexity of searching the rule set for a rule only relates to the depth of the tree, and if the depth of the tree is fixed, the time complexity is O(1). The definition of a full 16-ary ordered tree, its features,its creating and searching algorithms are presented.
Keywords:normal program behavior model  event  full 16-ary ordered tree  anomaly detection
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与科学》浏览原始摘要信息
点击此处可从《计算机工程与科学》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号