|
Today, the growing problem of computer security, whether it is the Unix buffer overflow, or Microsoft's Internet browser vulnerabilities, the computer system at all levels, there are security risks. However, the traditional security technologies are no longer meet people's needs. Therefore, a new tool for computer security - intrusion detection system, people's attention. This is a computer resource usage by detecting computer security systems to protect it as a traditional computer security solutions \. Currently, intrusion detection systems, there are three classifications: Technically, can be divided into feature-based intrusion detection systems and anomaly-based intrusion detection systems; from the data source, and can be divided into host-based intrusion detection system and network-based intrusion detection system; from the implementation structure, can be divided into single-point intrusion detection systems and intrusion detection systems. This subject's immune system from biological principles to be inspired, the whole act of intrusion detection interpreted as a detector to identify the \In this paper, the detector to simulate the organism lymphocytes, it also experienced dynamic process of generation to mature. With the constant evolution of sophisticated detector, can accurately detect the abnormal part of the detector on the evolution of memory detector, while the other part can not detect the abnormality detector is considered to be a self-reactions and discarded. In this paper, to the host computer resources for the study, the process by studying privileged system call sequences, feature-based detection and anomaly-based detection method of combining, and thus the host-based intrusion analysis and detection. Linux is currently available in view of the source code and access to its extensive use of the kernel of the operating system, built on this topic on the Linux platform. As experimental lt; WP = 3 gt; conditions, mainly studied in the experimental stage Sendmail privileged system calls the process conditions for such systems based on the host computer intrusion detection method calls made a clear overview of the interpretation . First, random length k of Linux system call sequences, these system calls sequences are called quasi detector. Then, in a laboratory environment under normal circumstances, the process of collecting Sendmail system call data and use these data STIDE technical normalization process. Using these processed data to train the neural network based on BP algorithm, and ultimately get a Sendmail process normal behavior pattern library. Subsequently, negative selection, the quasi-detector and the normal behavior patterns library system call sequence eleven comparison, the matching sequence is discarded, leaving only the sequence of system calls that do not match. System call sequence thus obtained is mature detector. Finally, these mature into the real environment of the detector in the inspection, and the detector be selected dynamically. In this selection process, the abnormality can be detected that the detector has become a memory detector saved for subsequent use of intrusion detection, and experienced a period of time after the actual detection is still not detected abnormality detector is considered a normal behavior patterns, be abandoned. Thus, after the accumulated training and testing, will be able to get along with the computer environment changes constantly improve their own, the latest detector, thereby obtaining a more perfect computer security solutions. In this paper, in order to verify the effectiveness of the method, the target host artificially launched three attacks: syslogd, sunsendmailcp, decode, a method of calculating the rate of false positives and false negatives obtained good experimental results.
|