基于D-S证据理论的主机违规行为检查方法
文献类型:期刊论文
作者 | 王斌 ; 连一峰 ; 陈恺 |
刊名 | Computer Applications and Software
![]() |
出版日期 | 2012 |
卷号 | 29期号:2页码:90-93,148 |
关键词 | D-S evidence theory Host violation Anomaly detection |
ISSN号 | 1000-386X |
其他题名 | host violation check method based on d-s evidence theory |
中文摘要 | 主机违规行为是能对主机及其所在信息系统的安全造成影响,或泄露主机上的重要信息的行为。提出一种主机违规检查方法,针对主机违规行为证据信息进行单一证 据源基础概率判定,并通过D-S证据理论对其进行融合,计算得到主机行为的违规系数,以此作为违规检查的判定依据。实验表明,该方法能够满足主机违规检查 工作的应用需求,具有较低的误报率和漏检率。 |
英文摘要 | Host violation is a such behaviour that it either breaks the security of the host and its information system or reveals the important information on the host.In this paper,a host violation checking method is proposed,which discriminates the underlying probability of single evidence resource aiming at the evidence information of each violation of host independently,and then fuses them based on D-S evidence theory,and attains violation coefficient of the host behaviour according to calculation,that will be considered as the discrimination basis for violation checking.Experiments indicate that by using this method,the application demand in host violation checking is able to be met with lower false alarm rate and missing rate. |
学科主题 | Computer Science |
收录类别 | cscd,cnki,wanfang |
语种 | 中文 |
公开日期 | 2012-11-12 |
源URL | [http://ir.iscas.ac.cn/handle/311060/14683] ![]() |
专题 | 软件研究所_软件所图书馆_期刊论文 |
推荐引用方式 GB/T 7714 | 王斌,连一峰,陈恺. 基于D-S证据理论的主机违规行为检查方法[J]. Computer Applications and Software,2012,29(2):90-93,148. |
APA | 王斌,连一峰,&陈恺.(2012).基于D-S证据理论的主机违规行为检查方法.Computer Applications and Software,29(2),90-93,148. |
MLA | 王斌,et al."基于D-S证据理论的主机违规行为检查方法".Computer Applications and Software 29.2(2012):90-93,148. |
入库方式: OAI收割
来源:软件研究所
浏览0
下载0
收藏0
其他版本
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。