Efficient Accurate Context-Sensitive Anomaly Detection  

Efficient Accurate Context-Sensitive Anomaly Detection

在线阅读下载全文

作  者:李红娇 李建华 

机构地区:[1]Dept.of Electronic Eng.,Shanghai Jiaotong Univ.

出  处:《Journal of Shanghai Jiaotong university(Science)》2007年第5期639-644,650,共7页上海交通大学学报(英文版)

摘  要:For program behavior-based anomaly detection, the only way to ensure accurate monitoring is to construct an efficient and precise program behavior model. A new program behavior-based anomaly detection model, called combined pushdown automaton (CPDA) model was proposed, which is based on static binary executable analysis. The CPDA model incorporates the optimized call stack walk and code instrumentation technique to gain complete context information. Thereby the proposed method can detect more attacks, while retaining good performance.For program behavior-based anomaly detection, the only way to ensure accurate monitoring is to construct an efficient and precise program behavior model. A new program behavior-based anomaly detection model, called combined pushdown automaton (CPDA) model was proposed, which is based on static binary executable analysis. The CPDA model incorporates the optimized call stack walk and code instrumentation technique to gain complete context information. Thereby the proposed method can detect more attacks, while retaining good performance.

关 键 词:program behavior-based anomaly detection system call combined pushdown automaton (CPDA) model 

分 类 号:TP309[自动化与计算机技术—计算机系统结构] TP316[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象