计算机应用 ›› 2013, Vol. 33 ›› Issue (08): 2244-2249.

• 信息安全 • 上一篇    下一篇

多维进程行为评估模型建立及最优化方法

毛琨1,2,杜学绘1,2,孙奕1,2   

  1. 1. 数字工程与先进计算国家重点实验室,郑州 450004
    2. 信息工程大学,郑州 450004;
  • 收稿日期:2013-02-08 修回日期:2013-03-27 出版日期:2013-08-01 发布日期:2013-09-11
  • 通讯作者: 毛琨
  • 作者简介:毛琨(1986-),男,辽宁大连人,硕士研究生,主要研究方向:信息安全、数据安全交换、进程安全;
    杜学绘(1968-),女,河南辉县人,教授,博士,主要研究方向:信息安全;
    孙奕(1979-),女,河南郑州人,讲师,博士研究生,主要研究方向:信息安全、数据安全交换。

Multiple-dimension process behavior evaluation model and its optimization

MAO Kun1,2,DU Xuehui1,2,SUN Yi1,2   

  1. 1. Information Engineering University, Zhengzhou Henan 450004, China
    2. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou Henan 450004, China
  • Received:2013-02-08 Revised:2013-03-27 Online:2013-09-11 Published:2013-08-01
  • Contact: MAO Kun

摘要: 针对目前进程行为评估模型所存在的模型优化问题和模型选取问题,定义进程行为,采用隐马尔可夫模型(HMM)来描述进程行为。讨论了准确率与误报率的关系,提出多维进程行为评估模型,以弥补单一进程行为评估模型的不足,基于布尔运算对多维进程行为评估模型进行融合,提高了评估性能。并基于代价决策树理论,给出了选取最优进程行为评估模型的目标函数,用于在融合后的多维进程行为评估模型上选择最优进程行为评估模型。最后,对所提出的多维进程行为评估模型的性能进行了测试,并与传统的STIDE和HMM方法进行了比较,结果证明了其有效性和优越性。

关键词: 进程行为, 异常检测, 多维进程行为评估模型, 布尔运算, 代价决策树, 最优进程行为评估模型

Abstract: To solve the existing problems of optimization and selection in process behavior evaluation model, the process behavior was defined, and the process behavior was described based on Hidden Markov Model (HMM). The relation between precision rate and false positives rate was discussed, and a multiple-dimension process behavior evaluation model based on Boolean function was proposed, which overcame the shortcomings of single process behavior evaluation model, and increased evaluation performance. On the basis of cost decision tree, the target function was given to select the optimal process behavior on the proposed evaluation model. Finally, the proposed evaluation model was tested and compared with the traditional Sequence TIme-Delay Embedding (STIDE) and HMM method. The test results verify the efficiency and superiority of the proposed model.

Key words: process behavior, anomaly detection, multiple-dimension process behavior evaluation model, Boolean function, cost decision tree, optimal process behavior evaluation model

中图分类号: