维普中文期刊产品整合服务

An Intrusion Detection Method Based on Hierarchical Hidden Markov Models

查看全文 作  者:JIA [1,2]Chunfu;YANG [2]Feng 高影响力作者 机构地区:[1]College of Information Science and Technology, Universityof Science and Technology of China, Hefei 230026, Anhui, China;;[2]College of Information Technology and Science, NankaiUniversity, Tianjin 300071, China高影响力机构 出  处:《Wuhan University Journal of Natural Sciences》索引2007年第12卷第1期,共4页高影响力期刊 基  金:Supported by the Science and Technology Development Project Foundation of Tianjin (033800611, 05YFGZGX24200) 摘  要:This paper presents an anomaly detection approach to detect intrusions into computer systems. In this approach, a hier- archical hidden Markov model (HHMM) is used to represent a temporal profile of normal behavior in a computer system. The HHMM of the norm profile is learned from historic data of the system’s normal behavior. The observed behavior of the system is analyzed to infer the probability that the HHMM of the norm pro- file supports the observed behavior. A low probability of support indicates an anomalous behavior that may result from intrusive activities. The model was implemented and tested on the UNIX system call sequences collected by the University of New Mexico group. The testing results showed that the model can clearly iden- tify the anomaly activities and has a better performance than hid- den Markov model. 关 键 词:计算机 网络技术 隐马尔可夫模型 安全技术
相关文献

参考文献(10)

引证文献(2)

耦合文献(1)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费