On Gray-Box Program Tracking for Anomaly Detection
Many host-based anomaly detection systems monitor a process ostensibly running a known program by observing the system calls the process makes. Numerous improvements to the precision of this approach have been proposed, such as tracking system call sequences, and various "gray-box" extensi...
Saved in:
Main Authors: | GAO, Debin, Reiter, Michael K., SONG, Dawn |
---|---|
格式: | text |
語言: | English |
出版: |
Institutional Knowledge at Singapore Management University
2004
|
主題: | |
在線閱讀: | https://ink.library.smu.edu.sg/sis_research/1241 http://dl.acm.org/citation.cfm?id=1251383 |
標簽: |
添加標簽
沒有標簽, 成為第一個標記此記錄!
|
相似書籍
-
Gray-Box Extraction of Execution Graphs for Anomaly Detection
由: GAO, Debin, et al.
出版: (2004) -
Towards Ground Truthing Observations in Gray-Box Anomaly Detection
由: MING, Jiang, et al.
出版: (2011) -
Behavioral Distance for Intrusion Detection
由: GAO, Debin, et al.
出版: (2005) -
Binhunt: Automatically Finding Semantic Differences in Binary Programs
由: GAO, Debin, et al.
出版: (2008) -
Automatically Adapting a Trained Anomaly Detector to Software Patches
由: LI, Peng, et al.
出版: (2009)