针对信息系统中内部人员的资源滥用行为,已有的检测方法要么不能有效检测新的资源滥用行为,要么需要获得资源滥用行为的先验知识,因而这些检测方法在应用中严重受限.本文提出了一种基于隐马尔可夫模型(HMM)的内部人员资源滥用行为检测方法.该模型以信息系统的敏感文件夹作为模型的状态,以用户的事务处理操作作为观测符号,采用Baum-Welch算法确定模型参数;基于该模型建立内部人员访问行为的HMM模型,并用于资源滥用行为检测.仿真结果表明了该检测方法的有效性.
The existing methods for resource misuse detection of information systems are restricted because of their own limitations,such as unable to detect new kinds of resource misuse and need the knowledge of potential misuses.A hidden Markov model(HMM) based method is presented to detect the resource misuse in information systems.In the HMM model,the file folders containing sensitive information are taken as the model states and the user operations as the model observation symbols.Baum-Welch algorithm is adopted to determine the model parameters.The behavioristic profiles of the insiders are determined by the HMM model and used to detect malicious behaviors.The simulation results show the effectiveness and adaptability of our method.