Dissertation > Excellent graduate degree dissertation topics show
Research of Anomaly Intrusion Detection Based on System Call
Author: LiuQuanYong
Tutor: LvFeng
School: Wuhan University of Technology
Course: Communication and Information System
Keywords: System calls KNN ( K - Nearest Neighbor ) Host Intrusion Detection
CLC: TP393.08
Type: Master's thesis
Year: 2006
Downloads: 103
Quote: 4
Read: Download Dissertation
Abstract
|
Intrusion detection technology based on the host system call sequence, called for the host system data to monitor a security technology. Host system call sequence reflects the behavioral characteristics of the system kernel, is conducive to the extraction of the characteristics of the system itself, and system monitoring, which can not consider differences identified from the legitimacy of the system behavior and destructive intrusion, effectively control and supervision of the privileged program used to identify the occurrence of abuse of power. Same time, this classification based on sequential patterns of sequence-based detection techniques, such as intrusion detection based on user command sequence can learn. This paper studies the detection of intrusion detection system based on the host system call classification algorithm. Key to call the intrusion detection model based on the host system is how to more accurately the system from the system call sequence for classification, introduction KNN classification algorithm applied to text classification system (K-Nearest Neighbor) originally used to detect whether or not the correct word algorithm inside the word. Text processing method, each system call is seen as a word in a very long document, and the set of system calls generated by a process as a share of the document. In this way the original method used to process text process complete application to intrusion detection problem. The KNN analysis is a new, KNN classification-based intrusion detection method. KNN algorithm is applied to the host-based intrusion detection system, the design of a Host Intrusion Detection System Based on KNN algorithm, the research, design work mainly includes the following aspects: an analysis of the current state of network security, intrusion technology and made a summary of its development; intrusion detection system based on system call basic principle and algorithm, and describes the KNN algorithm, the vector space description of the algorithm and eigenvalue calculation method; 3 design based on system calls Intrusion Detection System Model, introduced the design concept of the model described in the detailed implementation of the various functional modules of the model; 4 Finally, the algorithm was tested show that the the KNN algorithm of detection and classification accuracy is relatively high, it is a good intrusion detection classification algorithm.
|
Related Dissertations
- Design and Implementation of Intrusion Detection System Based on Artificial Immune Theory,TP393.08
- AdaBoost-based Linux host intrusion detection systems,TP393.08
- The Key Module of New-type Distributed Firewall System,TP393.08
- Research and Implementation of Firmware Architecture in Massive Parallel Computer,TP338
- Design and Implement of Collecting Data Module about HIDS under Virtual Machine UML,TP393.08
- System call based anomaly detection technology research,TP393.08
- Static analysis of program behavior based intrusion detection system research and design,TP393.08
- File system calls based intrusion detection system design and implementation,TP393.08
- Detection and Elimination of "Buffer-Overflow" Based on GECISM,TP393.08
- Research on Virtualization-based Capture Technology of Malicious Code Behavior,TP393.08
- Research on and Implementation of Desktop Security Defense System Key Technologies,TP309
- Research on Intrusion Detection Based on Privileged Process’ Behaviors,TP393.08
- Pioneer Network Device Driver Research and Implementation,TP311.1
- Micro Communication Element system architecture connectionless service in the design and implementation on the host,TP393
- Safety testing engine design and implementation,TP393.08
- Sequence inherent mode theory and application,TP311.13
- The Research System Robustness Testing Based on Fault Injection,TP311.52
- The Research and Implementation of Immunology-Based Intrusion Detection System,TP393.08
- The Anomaly Intrusion Detection Technology Based on System Call and IDS Extension function study,TP393.08
- The Research on Virtual Machine Based-on Xen,TP302
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|