Dissertation > Excellent graduate degree dissertation topics show

Intrusion Detection Based on Program’s Legal Function

Author: ZhangZhiFan
Tutor: WangYiGang
School: Donghua University
Course: Computer Software and Theory
Keywords: Network Security Intrusion Detection System calls Finite Automata Legitimate scope
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 33
Quote: 0
Read: Download Dissertation

Abstract


With the development of network technology and the expansion of the scope of application, it is increasingly dependent on information processing in the network. However, due to network attack tools and means of attack becomes more sophisticated and diverse, relying solely on the traditional network security measures has been unable to meet the requirements of network security. The face of the huge number and variety of changes in a variety of network attacks, it is necessary to establish efficient and flexible security precautions is a difficult and challenging task. Intrusion detection technology is developing rapidly in recent years, a new kind of network security technology. Host-based intrusion detection technology - both for known attack signatures or for system abnormalities - will focus on research and excavation for the attack process. Through research and analysis on the the malicious process model characteristics can to some extent prevent some attacks to cause harm to the system, but in the judgment of whether an action for malicious attacks but error-prone, resulting in a large number of false alarms. In this paper, starting from the point of view of the information security technology, describes the types and concept of intrusion detection systems, and intrusion detection system uses security technology Finally, through the analysis of the application in the system call execution sequence for large The majority of anomaly-based intrusion detection system easy given the widespread problem of false alarms, in-depth analysis of the root causes of the current system sends a miscarriage of justice, and proposes a new intrusion detection technology based on the essential difference between the user operations and malicious attacks. Accuracy by reducing error alarm rate, and improve the detection of attacks, allows administrators to focus more on the malicious attacks without being plagued by false alarms, greatly improving the efficiency of the system administrator. All key operations performed by the process must go through the system call to complete conversion from user mode to kernel mode, it can record sequence of system calls to get the process activities. When detected abnormal system call, can terminate the operation of the process, so that you can prevent the intrusion of malicious attacks on the system. Since the accuracy of system calls, difficult for an intruder to modify the system call to cover up the attack. The establishment of the legitimate scope based on call information to program the system using finite state automata modeling them. Every legitimate scope represented by a state, it contains a program run effective user marked and effective group designations, pursuant to which the detection of abnormal behavior of the system. The experimental results show that the method can detect attacks initiated by the application code loopholes and lower false alarm rate.

Related Dissertations

  1. The Research of Malware Detection Technology Based on Active Mode,TP393.08
  2. Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
  3. Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
  4. Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
  5. Region-based wireless sensor network key management scheme for research,TP212.9
  6. SX Provincial Public Security Bureau Network Security Corps Performance Evaluation Index System Design,D631.1
  7. Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
  8. The Research of Insurance Network Marketing of China Insurance Company,F724.6
  9. The Research on Intrusion Detection System Based on Machine Learning,TP393.08
  10. Research and Implemention of Information Security Encryption System Based on the RSA,TP309.7
  11. The Research of Attack Source Traceback in Distributed Denial-of-Service Attacks Based on VoIP,TP393.08
  12. Intrusion Detection in Mobile Ad Hoc Networks: A Timed Finite State Machines Approach,TN929.5
  13. Research on Streaming Media Detection Methods Against DoS\DDoS Attack Based on Analysis of Self-similarity,TP393.08
  14. Firewall and three switch - based campus network security policy research,TP393.08
  15. An Intrusion Detection System for High-Speed Networks,TP393.08
  16. Research on the Security in Wireless Sensor Network,TN915.08
  17. Research and Design of Secure Comunication of NVD on Demand System,TP309
  18. Sensitivity Analysis and Application of Orthogonal Weight Function Neural Network,TP183
  19. QH Software Services Marketing Strategy,F426.672
  20. Fast protocol identification based firewall system design and implementation,TP393.08
  21. IPsec-based remote access to corporate network systems design and implementation,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile