The Method of Classified Danger Sensed for Windows Process Intrusion Detection

Fei Xu, Chengyu Tan, Yi Zheng, M. Geng
{"title":"The Method of Classified Danger Sensed for Windows Process Intrusion Detection","authors":"Fei Xu, Chengyu Tan, Yi Zheng, M. Geng","doi":"10.1109/ICMECG.2009.72","DOIUrl":null,"url":null,"abstract":"Once the computer system is intruded, the change from normal to abnormal is a gradual procedure. Setting up a calculating model based on Danger Theory for danger signal during the procedure will improve the accuracy and efficiency of Artificial Immune System (AIS) greatly. In this paper, the method of classified danger sensed (MCDS) for Windows process intrusion detection based on Danger Theory is proposed. This method divides the process’s behavior parameters into two types: numeric and non-numeric types, using the function’s difference and correlation coefficient to analyze the rule and relevance of numeric parameters’ change, and evaluating the degree of danger of non-numeric parameters by analyzing the danger level and Time Relationship(TR) of data. Based on these methods, we establish calculating models of numeric and non-numeric danger signals separately, finally give the definition and calculating method of \" Danger Degree \".","PeriodicalId":252323,"journal":{"name":"2009 International Conference on Management of e-Commerce and e-Government","volume":"99 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-09-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 International Conference on Management of e-Commerce and e-Government","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICMECG.2009.72","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Once the computer system is intruded, the change from normal to abnormal is a gradual procedure. Setting up a calculating model based on Danger Theory for danger signal during the procedure will improve the accuracy and efficiency of Artificial Immune System (AIS) greatly. In this paper, the method of classified danger sensed (MCDS) for Windows process intrusion detection based on Danger Theory is proposed. This method divides the process’s behavior parameters into two types: numeric and non-numeric types, using the function’s difference and correlation coefficient to analyze the rule and relevance of numeric parameters’ change, and evaluating the degree of danger of non-numeric parameters by analyzing the danger level and Time Relationship(TR) of data. Based on these methods, we establish calculating models of numeric and non-numeric danger signals separately, finally give the definition and calculating method of " Danger Degree ".
Windows进程入侵检测中的分类危险感知方法
一旦计算机系统被入侵,从正常到异常的变化是一个渐进的过程。建立基于危险理论的过程中危险信号的计算模型,将大大提高人工免疫系统(AIS)的准确性和效率。提出了一种基于危险理论的Windows进程入侵检测分类危险感知方法。该方法将过程行为参数分为数值型和非数值型两类,利用函数的差分和相关系数分析数值参数变化的规律和相关性,通过分析数据的危险等级和时间关系(TR)来评价非数值参数的危险程度。在此基础上,分别建立了数值型和非数值型危险信号的计算模型,最后给出了“危险程度”的定义和计算方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信