YIN Qing-bo, ZHANG RU-bo, LI Xue-yao, et al. Research on Technology of Intrusion Detection Based on Dynamic Markov Model[J]. Acta Electronica Sinica, 2004, 32(11): 1785-1788.
YIN Qing-bo, ZHANG RU-bo, LI Xue-yao, et al. Research on Technology of Intrusion Detection Based on Dynamic Markov Model[J]. Acta Electronica Sinica, 2004, 32(11): 1785-1788.DOI:
A new method for anomaly intrusion detection is proposed based on dynamic Markov model.At first
behavioral features are extracted from the privileged processes
and then the Markov model is founded dynamically based on the features.The state sequences of dynamic Markov model are analyzed to infer the state probability
which is used to classify the normal or abnormal behavior.Because Markov model is constructed dynamically
it can extract the relationships of local behavioral features of the privileged processes adequately.When the training sets are limited
the method predicts exactly.The experiments show this method is simple
effective and efficient
and can be used in practice to monitor the computer system in real time.