LIU Hai-feng, QING Si-han, Meng Yang, et al. A New Audit-Based Intrusion Detection Model and Its Implement Mechanism[J]. Acta Electronica Sinica, 2002, 30(8): 1167-1171.
DOI:
LIU Hai-feng, QING Si-han, Meng Yang, et al. A New Audit-Based Intrusion Detection Model and Its Implement Mechanism[J]. Acta Electronica Sinica, 2002, 30(8): 1167-1171.DOI:
A New Audit-Based Intrusion Detection Model and Its Implement Mechanism
Intrusion detection models based on system call sequence are discussed
and a new intrusion detection model based on audit event vector which is named "AUDIDS" is presented.This model has not only the merits of the previous IDS model but also richer semantics and higher efficiency.We describe its implementation mechanism on Linux which defines
collects and stores audit event and improves the storage and matching of normal database.