ISCAS OpenIR
基于属性数据的系统调用过滤方法
其他题名Attribute-based methods for system call filtering
郭航; 连一峰
2014
发表期刊计算机工程与设计
ISSN1000-7024
卷号35期号:8页码:2621-2627
摘要针对现有系统调用过滤方法的局限性,对如何有效准确地精简系统调用日志进行研究,分析系统调用日志中涉及网络攻击的重要系统调用信息,提出一种基于属性数据的系统调用过滤方法。通过追踪和分析系统调用的属性数据,引入系统调用依赖规则,在确保准确性的前提下,对系统调用日志进行合理有效地精简、过滤;在此基础上,实现一个名为“系统调用分离器”的过滤工具。通过实验验证了该方法及工具的有效性和适用性。 Due to the limitations of the existing methods for system call filtering ,an issue that how to filter system call logs more efficiently was studied ,and the important information of system calls relating to network attacks was analyzed .Therefore an at-tribute-based method for system call filtering was proposed .Through tracing and analyzing all the needed attributes of system calls ,system call dependency rules were used .The huge system call logs were filtered in a more efficient and effective way on the premise of ensuring the filtering accuracy .Based on this ,a system call filtering tool called Separator was implemented and tested in experiments .
收录类别CSCD
其他摘要Due to the limitations of the existing methods for system call filtering, an issue that how to filter system call logs more efficiently was studied, and the important information of system calls relating to network attacks was analyzed. Therefore an attribute-based method for system call filtering was proposed. Through tracing and analyzing all the needed attributes of system calls, system call dependency rules were used. The huge system call logs were filtered in a more efficient and effective way on the premise of ensuring the filtering accuracy. Based on this, a system call filtering tool called Separator was implemented and tested in experiments.
关键词系统调用 系统对象 属性数据 系统调用依赖规则 网络攻击 System Call System Objects Attribute System Call Dependency Rules Network Attack
部门归属中国科学院软件研究所,北京100190; 中国科学院大学,北京100049 中国科学院软件研究所,北京,100190
语种中文
CSCD记录号CSCD:5222484
内容类型期刊论文
URI标识http://ir.iscas.ac.cn/handle/311060/16715
专题中国科学院软件研究所
推荐引用方式
GB/T 7714
郭航,连一峰. 基于属性数据的系统调用过滤方法[J]. 计算机工程与设计,2014,35(8):2621-2627.
APA 郭航,&连一峰.(2014).基于属性数据的系统调用过滤方法.计算机工程与设计,35(8),2621-2627.
MLA 郭航,et al."基于属性数据的系统调用过滤方法".计算机工程与设计 35.8(2014):2621-2627.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[郭航]的文章
[连一峰]的文章
百度学术
百度学术中相似的文章
[郭航]的文章
[连一峰]的文章
必应学术
必应学术中相似的文章
[郭航]的文章
[连一峰]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。