|
计算机应用研究 2009
Access control-based host anomaly intrusion detection model
|
Abstract:
The model of intrusion detection based on access control(ACBIDS) was proposed under the precondition of positive access reference by access control mechanism, in which combined advantage of access control and intrusion detection respectively. Constructed the activity associate graph based on direct acyclic graph (DAG) according to restriction relations among system call functions, and constructed divergence function about activity associated graph for computing the match degree between actual system call sequence and activity associated graph. The ACBIDS could detect the intrusion action in host finally. The experiment shows this model implements low false positive rate and low false negative rate, and upper efficiency.