Dissertation > Excellent graduate degree dissertation topics show
Research of Host-based Intrusion Prevention System Based on Process Behavior
Author: YueJunZuo
Tutor: CuiGuoHua
School: Huazhong University of Science and Technology
Course: Computer technology
Keywords: Active Controllability Defense Host Intrusion Prevention System Action Monitor API HOOK
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 41
Quote: 2
Read: Download Dissertation
Abstract
|
The topic is a expansion of Central China Power Grid’s project named“Computer Terminal Protection System”, which mainly for the situation of the week of the current computer security system protection to the end and passive defensive-oriented, studied and implemented a Host Intrusion Prevention System which compensate for this short coming and could be more effective and active. It is based on active controllability defense theory, using a variety of security technologies and a App-Sys model, implement security defense by collecting information and managing and maintaining this information.The computer terminal, whether the host or server, which’s activity is achieved by the process, while the process runs inseparable from the operating system. And the application of more current operating system comes as Windows, that is, even when the attack occurred around the installation of the operating system on top of security software, it can not do without the support of the operating system service routine. Host Intrusion Prevention System, as a last defense line of security protection, the operation of the process, including file operations, registry operations, etc. closely monitor the implementation of each action will be to follow-up analysis to ensure the security of the host.It has researched on the mechanism of Windows kernel-model system application, the use of SSDT HOOK technology, which achieved the interception of the system application, develop the code on the kernel layer more than on the application layer is not easy for malicious code to avoid.Intrusion prevention system make the defense in the system level, using the kernel API HOOK against a variety of attacks of unknown viruses. It uses the access control policies that come from users, makes the projection of registry, file.tec the truth. Ensuring process’s safe operation by prevent itself from killing. Through the control of program execution, not only can prevent unknown program is running, you can prevent malicious code attacks. Through these protection, upgrading the operating system’s security.System simulation test results show that the system from the process monitor, registry monitor, file monitor multiple aspects, through secure access on the system behavior rules of effective control and protection system behavior monitoring module takes less system resources in the case of Efficient implementation of the process, file, registry protection, pre-design to achieve the goal, to a good defense against unknown viruses.
|
Related Dissertations
- BHO malicious Web -based technology research and implementation of behavior detection technology,TP393.092
- Detection and Behavior Analysis of Malicious Code,TP393.08
- General information extraction specific person screen than on software design and implementation,TP311.52
- The Design and Implement of Malware Behavior Detection System Based on Decision Tree,TP393.08
- Research and Application of Small-scale Host Intrusion Prevent System,TP393.08
- The Research on the Theory and Technique of Protection Against Trojan Horse Attack,TP393.08
- Host intrusion protection technology research,TP393.08
- Research and Implementation of the Technology Against HIPS Under WIN32 Platform,TP393.08
- The Designe and Key Modules Realization of Distributed Software Performance Testing Tools,TP311.52
- Internal network design and implementation of early warning systems,TP393.1
- Research on File Access Control Based on Intranet,TP393.08
- A Study on the Technique of the Monitoring Mobile Device Based on USB,TP277
- Design and Implementation of Stealth Backdoor,TP311.11
- The Design and Realization of English to Chinese and Mongolian Electronic Dictionary Computer Inquiring Software,TP311.52
- The Design and Implement of File Nonproliferation System in Windows Environment,TP311.52
- The Research and Design of Behavior-based Host Intrusion Prevention System,TP393.08
- Research on Security Audit System of Intranet and Audit Data Mining,TP311.13
- The Study and Realization of "English-Chinese-Mongolian Electronic Dictionary",TP311.52
- Electronic Document Security Platform for the Entire Life Cycle,TP393.08
- The Study and Implementation of Action Monitoring in the Host Intrusion Protection System,TP393.08
- Research on Intrusion Detection Based on Feature Selection,TP393.08
- Analysis on DDoS Attacks Detecting Technology Based on Eigenvector,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|