收录:
摘要:
In this paper, we propose a new trusted modeling approach based on state graphs. We introduce a novel method of deriving state-layer from a system call sequence in terms of probability and statistics theory, and we identify the state sequence with the help of Hidden Markov Model (HMM). We generate state transition graph according to software executing process and pruning rules. Then, we separate local function graphs according to software specific functions by semantic analysis. The state-layer is a bridge between the basic behaviors and the upper layer functions of software to compensate semantic faults. In addition, a pruning strategy of formulating state graphs is designed to precisely describe each piece of software functions. Finally, a detecting system based on our model is proposed, and a case study of RSS software reveals how our system works. The results demonstrate that our trusted model describes software behaviors successfully and can well detect un-trust behaviors, anomaly behaviors, and illegal input behaviors.
关键词:
通讯作者信息:
电子邮件地址:
来源 :
IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS
ISSN: 1745-1361
年份: 2014
期: 3
卷: E97D
页码: 488-496
0 . 7 0 0
JCR@2022
ESI学科: COMPUTER SCIENCE;
ESI高被引阀值:188
JCR分区:4
中科院分区:4
归属院系: