HMM-Based Detection Method for Misuse of Resource in Information Systems
电子学报2010年38卷第6期 页码:1383-1388
作者机构:
作者简介:
基金信息:
DOI:
中图分类号:TP309.2
纸质出版:2010
稿件说明:
移动端阅览
FONT face, Verdana, 王 超, 等. 基于隐马尔可夫模型的资源滥用行为检测方法研究[J]. 电子学报, 2010,38(6):1383-1388.
FONT face, Verdana, WANG Chao, et al. HMM-Based Detection Method for Misuse of Resource in Information Systems[J]. Acta Electronica Sinica, 2010, 38(6): 1383-1388.
FONT face, Verdana, 王 超, 等. 基于隐马尔可夫模型的资源滥用行为检测方法研究[J]. 电子学报, 2010,38(6):1383-1388.DOI:
FONT face, Verdana, WANG Chao, et al. HMM-Based Detection Method for Misuse of Resource in Information Systems[J]. Acta Electronica Sinica, 2010, 38(6): 1383-1388.DOI:
<FONT face=Verdana>The existing methods for misuse detection of information systems are restricted because of their own limitations
such as unable to detect new kinds of misuse and need the knowledge of potential misuses. A hidden Markov model (HMM) based method is presented to detect the misuse of resource in information systems. In the HMM model
the file folders containing sensitive information are taken as the model states and the user operations as the model observation symbols. Baum-Welch algorithm is adopted to determine the model parameters. The behavioristic profiles of the insiders are determined by the HMM model and used to detect malicious actions. The simulation results show the effectiveness and adaptability of our method.