中国科学院机构知识库网格
Chinese Academy of Sciences Institutional Repositories Grid
基于D-S证据理论的主机违规行为检查方法

文献类型:期刊论文

作者王斌 ; 连一峰 ; 陈恺
刊名Computer Applications and Software
出版日期2012
卷号29期号:2页码:90-93,148
关键词D-S evidence theory Host violation Anomaly detection
ISSN号1000-386X
其他题名host violation check method based on d-s evidence theory
中文摘要主机违规行为是能对主机及其所在信息系统的安全造成影响,或泄露主机上的重要信息的行为。提出一种主机违规检查方法,针对主机违规行为证据信息进行单一证 据源基础概率判定,并通过D-S证据理论对其进行融合,计算得到主机行为的违规系数,以此作为违规检查的判定依据。实验表明,该方法能够满足主机违规检查 工作的应用需求,具有较低的误报率和漏检率。
英文摘要Host violation is a such behaviour that it either breaks the security of the host and its information system or reveals the important information on the host.In this paper,a host violation checking method is proposed,which discriminates the underlying probability of single evidence resource aiming at the evidence information of each violation of host independently,and then fuses them based on D-S evidence theory,and attains violation coefficient of the host behaviour according to calculation,that will be considered as the discrimination basis for violation checking.Experiments indicate that by using this method,the application demand in host violation checking is able to be met with lower false alarm rate and missing rate.
学科主题Computer Science
收录类别cscd,cnki,wanfang
语种中文
公开日期2012-11-12
源URL[http://ir.iscas.ac.cn/handle/311060/14683]  
专题软件研究所_软件所图书馆_期刊论文
推荐引用方式
GB/T 7714
王斌,连一峰,陈恺. 基于D-S证据理论的主机违规行为检查方法[J]. Computer Applications and Software,2012,29(2):90-93,148.
APA 王斌,连一峰,&陈恺.(2012).基于D-S证据理论的主机违规行为检查方法.Computer Applications and Software,29(2),90-93,148.
MLA 王斌,et al."基于D-S证据理论的主机违规行为检查方法".Computer Applications and Software 29.2(2012):90-93,148.

入库方式: OAI收割

来源:软件研究所

浏览0
下载0
收藏0
其他版本

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。