• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Lai, Yingxu (Lai, Yingxu.) (学者:赖英旭) | Zhang, Wenwen (Zhang, Wenwen.) | Yang, Zhen (Yang, Zhen.) (学者:杨震)

收录:

EI Scopus SCIE

摘要:

Current software behavior models lack the ability to conduct semantic analysis. We propose a new model to detect abnormal behaviors based on a function semantic tree. First, a software behavior model in terms of state graph and software function is developed. Next, anomaly detection based on the model is conducted in two main steps: calculating deviation density of suspicious behaviors by comparison with state graph and detecting function sequence by function semantic rules. Deviation density can well detect control flow attacks by a deviation factor and a period division. In addition, with the help of semantic analysis, function semantic rules can accurately detect application layer attacks that fail in traditional approaches. Finally, a case study of RSS software illustrates how our approach works. Case study and a contrast experiment have shown that our model has strong expressivity and detection ability, which outperforms traditional behavior models.

关键词:

system call software behavior deviation density state graph semantic analysis function semantic rules

作者机构:

  • [ 1 ] [Lai, Yingxu]Beijing Univ Technol, Coll Comp Sci, Beijing, Peoples R China
  • [ 2 ] [Yang, Zhen]Beijing Univ Technol, Coll Comp Sci, Beijing, Peoples R China
  • [ 3 ] [Zhang, Wenwen]Beijing Univ Technol, Beijing, Peoples R China

通讯作者信息:

  • 赖英旭

    [Lai, Yingxu]Beijing Univ Technol, Coll Comp Sci, Beijing, Peoples R China

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS

ISSN: 1745-1361

年份: 2015

期: 10

卷: E98D

页码: 1777-1787

0 . 7 0 0

JCR@2022

ESI学科: COMPUTER SCIENCE;

ESI高被引阀值:168

JCR分区:4

中科院分区:4

被引次数:

WoS核心集被引频次: 1

SCOPUS被引频次: 1

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 3

在线人数/总访问数:807/3889950
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司