论文部分内容阅读
针对现有系统调用过滤方法的局限性,对如何有效准确地精简系统调用日志进行研究,分析系统调用日志中涉及网络攻击的重要系统调用信息,提出一种基于属性数据的系统调用过滤方法。通过追踪和分析系统调用的属性数据,引入系统调用依赖规则,在确保准确性的前提下,对系统调用日志进行合理有效地精简、过滤;在此基础上,实现一个名为“系统调用分离器”的过滤工具。通过实验验证了该方法及工具的有效性和适用性。
Aiming at the limitations of the existing system call filtering methods, this paper studies how to effectively and accurately reduce system call logs, analyzes important system call information involved in network attacks in system call logs, and proposes a system call filtering method based on attribute data. By tracing and analyzing the attribute data of the system call, the introduction of the system call dependency rules, to ensure the accuracy of the premise of the system call log reasonably and efficiently streamlined and filtered; on this basis, to achieve a called “system call separation Filter ”filter tool. The effectiveness and applicability of the method and tool are verified by experiments.