作者
Steven A Hofmeyr, Stephanie Forrest, Anil Somayaji
发表日期
1998/1/1
期刊
Journal of computer security
卷号
6
期号
3
页码范围
151-180
出版商
IOS Press
简介
A method is introduced for detecting intrusions at the level of privileged processes. Evidence is given that short sequences of system calls executed by running processes are a good discriminator between normal and abnormal operating characteristics of several common UNIX programs. Normal behavior is collected in two ways: Synthetically, by exercising as many normal modes of usage of a program as possible, and in a live user environment by tracing the actual execution of the program. In the former case several types of intrusive behavior were studied; in the latter case, results were analyzed for false positives.
引用总数
199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320241419335185115137123142137123105115949296116878475747655444514
学术搜索中的文章
SA Hofmeyr, S Forrest, A Somayaji - Journal of computer security, 1998