Overview of Anomaly Detection Based on Program
暂无分享,去创建一个
In terms of methods describing normal program behavior,anomaly detection based on program can be grouped into several broad categories:specification-based,frequency-based,control-flow-based,and data-flow-based.After reviewing systematically the basic ideas and various models used in these approaches,discussing the new advances of the technique,pointing out and analyzing some problems and weaknesses which exist in current research,this paper formulated a notion that anomaly detection based on program should focus attention on various server programs.A system prototype based on the hierarchical structure of server programs' traces and validated by a preliminary experiment was simply introduced.The prototype is capable of analyzing anomalous events and providing detailed information with respect to intrusion,and these abilities are just the trend for more research of anomaly detection.