利用系统漏洞实施攻击是目前计算机安全面临的主要威胁.本文提出了一种基于进程行为的异常检测模型.该模型引入了基于向量空间的相似度计算算法和反向进程频率等概念,区分了不同系统调用对定义正常行为的不同作用,提高了正常行为定义的准确性;该模型的检测算法针对入侵造成异常的局部性特点,采用了局部分析算法,降低了误报率.
More and more intruders exploit the vulnerabilifies of system and applications to intrude the system. This paper introduced an anomaly intrusion detection model analyzing processes' behaviors. It introduces the similarity calculation method based on Vector-space. And it introduces an argument to value the capabilities of system calls to differentiate the process behaviors. Thinking of the characters of the abnormalities caused by intrusions, the detection algorithm adopts the method of locally analyzing.