中国科学院软件研究所机构知识库
Advanced  
ISCAS OpenIR  > 软件所图书馆  > 期刊论文
Title:
基于属性数据的系统调用过滤方法
Alternative Title: Attribute-based methods for system call filtering
Author: 郭航 ; 连一峰
Keyword: 系统调用 ; 系统对象 ; 属性数据 ; 系统调用依赖规则 ; 网络攻击 ; system call ; system objects ; attribute ; system call dependency rules ; network attack
Source: 计算机工程与设计
Issued Date: 2014
Volume: 35, Issue:8, Pages:2621-2627
Indexed Type: CSCD
Department: 中国科学院软件研究所,北京100190; 中国科学院大学,北京100049 中国科学院软件研究所,北京,100190
Abstract: 针对现有系统调用过滤方法的局限性,对如何有效准确地精简系统调用日志进行研究,分析系统调用日志中涉及网络攻击的重要系统调用信息,提出一种基于属性数据的系统调用过滤方法。通过追踪和分析系统调用的属性数据,引入系统调用依赖规则,在确保准确性的前提下,对系统调用日志进行合理有效地精简、过滤;在此基础上,实现一个名为“系统调用分离器”的过滤工具。通过实验验证了该方法及工具的有效性和适用性。 Due to the limitations of the existing methods for system call filtering ,an issue that how to filter system call logs more efficiently was studied ,and the important information of system calls relating to network attacks was analyzed .Therefore an at-tribute-based method for system call filtering was proposed .Through tracing and analyzing all the needed attributes of system calls ,system call dependency rules were used .The huge system call logs were filtered in a more efficient and effective way on the premise of ensuring the filtering accuracy .Based on this ,a system call filtering tool called Separator was implemented and tested in experiments .
English Abstract: Due to the limitations of the existing methods for system call filtering, an issue that how to filter system call logs more efficiently was studied, and the important information of system calls relating to network attacks was analyzed. Therefore an attribute-based method for system call filtering was proposed. Through tracing and analyzing all the needed attributes of system calls, system call dependency rules were used. The huge system call logs were filtered in a more efficient and effective way on the premise of ensuring the filtering accuracy. Based on this, a system call filtering tool called Separator was implemented and tested in experiments.
Language: 中文
Citation statistics:
Content Type: 期刊论文
URI: http://ir.iscas.ac.cn/handle/311060/16715
Appears in Collections:软件所图书馆_期刊论文

Files in This Item:

There are no files associated with this item.


Recommended Citation:
郭航,连一峰. 基于属性数据的系统调用过滤方法[J]. 计算机工程与设计,2014-01-01,35(8):2621-2627.
Service
Recommend this item
Sava as my favorate item
Show this item's statistics
Export Endnote File
Google Scholar
Similar articles in Google Scholar
[郭航]'s Articles
[连一峰]'s Articles
CSDL cross search
Similar articles in CSDL Cross Search
[郭航]‘s Articles
[连一峰]‘s Articles
Related Copyright Policies
Null
Social Bookmarking
Add to CiteULike Add to Connotea Add to Del.icio.us Add to Digg Add to Reddit
所有评论 (0)
暂无评论
 
评注功能仅针对注册用户开放,请您登录
您对该条目有什么异议,请填写以下表单,管理员会尽快联系您。
内 容:
Email:  *
单位:
验证码:   刷新
您在IR的使用过程中有什么好的想法或者建议可以反馈给我们。
标 题:
 *
内 容:
Email:  *
验证码:   刷新

Items in IR are protected by copyright, with all rights reserved, unless otherwise indicated.

 

 

Valid XHTML 1.0!
Copyright © 2007-2020  中国科学院软件研究所 - Feedback
Powered by CSpace