• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Lai, Yingxu (Lai, Yingxu.) (学者:赖英旭) | Zhang, Wenwen (Zhang, Wenwen.) | Yang, Zhen (Yang, Zhen.) (学者:杨震)

收录:

EI Scopus SCIE

摘要:

In this paper, we propose a new trusted modeling approach based on state graphs. We introduce a novel method of deriving state-layer from a system call sequence in terms of probability and statistics theory, and we identify the state sequence with the help of Hidden Markov Model (HMM). We generate state transition graph according to software executing process and pruning rules. Then, we separate local function graphs according to software specific functions by semantic analysis. The state-layer is a bridge between the basic behaviors and the upper layer functions of software to compensate semantic faults. In addition, a pruning strategy of formulating state graphs is designed to precisely describe each piece of software functions. Finally, a detecting system based on our model is proposed, and a case study of RSS software reveals how our system works. The results demonstrate that our trusted model describes software behaviors successfully and can well detect un-trust behaviors, anomaly behaviors, and illegal input behaviors.

关键词:

system call trust state graph software behavior state-layer

作者机构:

  • [ 1 ] [Lai, Yingxu]Beijing Univ Technol, Beijing, Peoples R China
  • [ 2 ] [Zhang, Wenwen]Beijing Univ Technol, Beijing, Peoples R China
  • [ 3 ] [Yang, Zhen]Beijing Univ Technol, Beijing, Peoples R China

通讯作者信息:

  • 赖英旭

    [Lai, Yingxu]Beijing Univ Technol, Beijing, Peoples R China

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS

ISSN: 1745-1361

年份: 2014

期: 3

卷: E97D

页码: 488-496

0 . 7 0 0

JCR@2022

ESI学科: COMPUTER SCIENCE;

ESI高被引阀值:188

JCR分区:4

中科院分区:4

被引次数:

WoS核心集被引频次: 1

SCOPUS被引频次: 1

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 3

归属院系:

在线人数/总访问数:569/3894545
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司