arrow
返回

SHADuDT: Secure hypervisor-based anomaly detection using danger theory

delete2013-11-01
delete8
PRE
AI
R
Reza Azmi
P
Pishgoo, Boshra *
DOI:10.1016/j.cose.2013.08.005delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Intrusion Detection based upon learning methods is an attractive approach in research community. These researches have two critical concerns: secure information gathering and accurate detection method. Here we used system calls together with their arguments as a suitable pattern for describing behavior of each process. In security applications, these patterns must be collected safely, so we proposed SHADuDT, a secure and robust hypervisor-based architecture for system call intercepting and information gathering that utilizes the second generation of Artificial Immune Systems (AIS) as intrusion detection method. Generally intrusion detection based on AISs fall into two categories. The first generation of AIS is inspired from adaptive immune reactions but the second one that is called danger theory focuses on both of these reactions to build a more biologically- ' realistic model of Human Immune System. Here we presented a novel Algorithm in Danger Theory field as SHADuDT detection method (SHADuDT_DM) for anomaly detection and utilized hypervisor architecture for SHADuDT secure auditor (SHADuDT_SA) to guarantee the safety of information gathering. We evaluated SHADuDT architecture through several criteria and compared its detection method with classic AIS methods for anomaly detection. These Evaluation results show considerable improvements in terms of detection performance and false alarm rates while keeping low overheads in execution time and memory by using the advantages of both hypervisor technology and Artificial Immune Systems. (C) 2013 Elsevier Ltd. All rights reserved.
Keyword:
Intrusion detection system
Anomaly detection
Artificial immune system
Danger theory
Hypervisor technology
System call interception
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

A
Alzahra University
学者数:
1.4K
论文数: 1.3K
被引数: 1.1K
引用论文

引用论文

Intrusion detection via system call traces
err1997-01-01
err153
PREAI
errKosoresow, AP; Hofmeyr, SA
err分享
err收藏
err分享
err收藏
Gene-Specific Function Prediction for Non-Synonymous Mutations in Monogenic Diabetes Genes
err2014-08-19
err0
errOAAI
errQuan Li; Xiaoming Liu; Richard A. Gibbs; Eric Boerwinkle; Constantin Polychronakos; Hui-Qi Qu
err分享
err收藏
Economic Impacts of Citrus Greening (HLB) in Florida, 2006/07–2010/11
errEDIS
IF0
err2012-01-31
err0
errOAAI
errAlan W. Hodges; Thomas H. Spreen
err分享
err收藏
err分享
err收藏
学者 查看更多内容