文中提出了一种针对计算网格U2R攻击的主机入侵检测技术,在主机层使用BV方法,以降低漏报率和误报率.在主机操作系统内核中使用基于整数比较实现的BV方法,不仅占用较小的系统开销,而且可对主机关键资源的使用进行检测.同时通过整合网格访问控制机制,在网格环境下准确地标识入侵者,并向网格中间件层提供网格用户使用主机资源的信息为进一步的用户行为分析提供支持.
In the paper,a Host-based Intrusion Detection technology for computing grid was proposed which employs Bottleneck Verification(BV)approach to detect U2R intrusions with both low false alarm rate and high detection rate.Due to working inside operating system kernel and performing BV by integer comparison,the technology achieves more efficiency and accuracy.More important,for analyzing suspicious Grid user s behavior,instead of reporting suspicious events indexed by local user ID to high level Grid-based Intr...