• 沒有找到結果。

以視窗登錄機碼為基礎之使用者行為異常偵測方法

N/A
N/A
Protected

Academic year: 2021

Share "以視窗登錄機碼為基礎之使用者行為異常偵測方法"

Copied!
7
0
0

加載中.... (立即查看全文)

全文

(1)















































































































































































































































[email protected] [email protected] [email protected]

















                      ! " #$  % & ' ( )#* + , -. /0 1 * +2 3 4 5 67 8 6 9 :  ; 0 <  = > ? 0 @ A  B C D

E)  F GHI (Windows Registry) J K A

 Windows L   M@ N ! " O

K  PQ RSTUV W X Y Z $[\ ]  ^ _ ` ab c@ de  F GHIfg h ij   F GHIkl m n oH(Support Vector

Machine, SVM)]p q -r s  , D E5 67

8 6)tu v wEx y G  F GHI` a?dz  , 5 6D E{` aX | /} ;~  ` aX |  E€ X | ‚ƒ „ SVM …5 6† ‡€ ˆ ?T‰ TŠ‹ , D E Œ 8 69 : Ž)$ tu #  F G HIk SVM ‘ ’ …“ ” • T–— ˜ @ X | ™ š ‚› œ SVM € žš )tu Ÿ   ¡¢£  , D E8 6r s  ¤ ¥‚¦ § ¨ © † ª « ¬?­ ® tu  0Н 8 6 D EŽ) _ °± ² , D EP  F GHIPl m n o HP8 6r s

1.

















 ³ ´ µ ¶ · ¸ · ¹ º » ´ ¼ ½ · ¾ ¸ L M  2 3            ¿ À Market Share 2006Á” ÂÃ Ä [12]Å Æ Ç È É Ê Ë ÌT ÍZ $6 ÎÏ Ð 2 Ñ )ÒÓ Ô * + Õ ÅÍ/ B C W Ö  ;c# , × ÌØ [Ù Ú kÛ Ü ) x Ý Þ  , A* +Í` a-ß à  , 5 6D E‚T~  D EJ K 5 6D E † ‡;áD Ek$5 6† ‡^ Ç â ?TŠ‹ Œ 8 6D E Ž)…$¢ , D EMŠ ‹Å2 Aã ®  , ä åÒ.  ~  D Eæ Eç ß  , …¡)èéÝ Þ  , D Eê åë ì í )  F GHI [11] M @ [oÓÔ * + X Y /0T  F GHI-J î 5 6D E† ‡‚x $¢5 6† ‡-Š‹ , D EŒ  Ž8 6ï ;ð ñ 8 6„ ò r s Mó ¢ô v w) A  F GHIM@ ! " F GHIU Å^ #Q °k°õö ÷ RSb cj  e  F GHI [2])ó ¢v ø  , A * +žc Åù RSú ûü 1 Eý þ ë   , A ë ô p Q RS” Âüü oüp RSô p  þ TÍ ,  ^ RSxü ,  ë ô p MRSˆ ü ,  p Q RS)ü  —   W  ú û  q Pž Y Pi W M  , A Å W  ù [\ ] ë ^ Z $  u AF GHIÍG ë    / B C RSAÖ D žÅ#F GHIMa ë ^  TF GHI?TE ¡8 6D EM   X Y )   1.                   A B C D E F   q o x o o o o ž Y o o o o o o i 4  o o o o o o  W o o x o x x ! " # N x o o o o o $ % W x x o x x o FTPW x x o   o = & '     o  ( ) W o o o    $ * W x x     + , Q  x x    x fhið¡' ( v w-é. /dRS

k  F GHI0 a¨ ¥…E5 6† ‡€ 

X | 1 2 .  l m n o H(Support Vector Machine, SVM) [8][9]D € TJ î -Š‹ Œ 8 6D EŽM5 6† ‡) A , D E8 69 :Н Í?0c T {3ô 9  ² (1)4 5 8 6¨ ¥²4 5 8 6¨ ¥ŽûÅ   ,  7 B C RS„ ò ) (2) , 5 ä D E6 7 ² , 5 8  9  k 6 ¨ ¥ ¡„ ) (3)9 , 5 6D E J K M† ‡ë : ; < ²û ;   , % = áQ RSŠß E8 6¨ ¥ Ž)$¨ ¥‚ë L „ fhiM> ? > @ )

(2)

TÍA3B  ÅC B AfhiMb ß à E8 6D EŽtu 0x  fhi ð¡Mv w‰ TŠ‹E8 6) fi]Eý D E {-AF D ;cG H   F GHIA„ ò r s ÍQ TU , † ‡ J K k SVM M^ _ ' ( )A3D ;. ® û T   F GHIE  ‚j  SVM …5 6† ‡ J K TUD E]p )AI D Efhi ð¡ v wJ K ‚L ‰ . ® ӋM Nk† OTU « ¨ ¥)AP D ˆ TQ ô ë ¨ © -‰ T« ¬T­ « f' ( ð¡v wæ « 0 < Š‹ ¡8 6 Ž)2 Aý D 𡑠hUR -' ( v n )

2.

































ö ÷ RS Sk  F GHI …0 aTÅ#  F GHI ` a ÅU V @ A [2][\ ]RS ARSW a P ‘ X ž  7 Yš Z ¢[žš @ d e F GH I\/d  F GHI` a9 :] 0 1  Ö 9 :) A Apap [2]' ( Î, j ^ E RAD

(Registry Anomaly Detection) -_ ` RS#

F GHI@ d9  ‚T¢ô a v w-Š ¯ ~  @ d¨ ¥Œ 8 6r s ¡B C W ) A   F G H I M   X Y  Âb T ° õPÂb ô p PÂb ‘ c P¡Âb éd  Re ^ fPTUÂb Œ Ìg hX Y E-){E Âb MX Y 9 :² Process: aim.exe Query: QueryValue Key:HKCU\Software\AmericaOnline\AOLInstantMes senge(TM)\CurrentVersion\Users\aimuser\Login\Pass word Response: SUCCESS ResultValue: “ BCOFHIHBBAHF” TÍX Y üa aim.exeRSÂb Å@ N   F GHIΉ i § i Iõtu ?z j Åk l E¢Ìg Âb Tʼn i § i IõE“BCOFHIHBBAHF”)   F GHI#_ ` Ï Ð D Em 6 <

 Ain [2] ' ( , ðUZ E[" Ï

Ð RScj     #  F GH I9o 6 7   F GHIpì ûq 6 HKLM\Software\Microsoft\Windows\CurrentVersion\ RunTæ r Ï Ð RS0: A-HÍÖ Z $ [" Ï Ð RS  Ž` aD E ¡8 6   F GHI@ dD E) SVM ¢ j  H q s  t u w  ] p w [7][8][9]Z E ?1 v w x f 2 ë y z {  \2 3 . 6  A8 6„ ò r s | } M) ú û Chen [3] ~  SVM -…„ ò r s , ; SVM k p  . + ,  ] p 0€ … Ç â   SVM ]p 0€ ‚ p  . + , )AWang [6]  iƒ  G H ô T„ ¢ p ‹ l m n oH

(One-Class Support Vector MachinesOCSVM) …

8 6 r s  v w  ‚T ­ ® Å r s 0€ ‚  STIDE k… ?† ‡ 8 6r s ) . ͈ ^ _ ' ( ðñ X Y fhið ¡¢£ ‘ ’   F GHIk SVM M T‰ 0 : # , D E8 69 :0 < ‰ TŠ‹)T {;G H fhi#  F GHIM 9  . ® TU  SVMô p Š d‚#‘ ’ M2 ‹ -z { …’ “ ” • )

3.









































!

!

!

!

"

"

"

"

#

#

#

#

SVM

3.1 





































¢ÓŒ X | Š d#€  , D E† ‡-.  Ž éM NT¢ÓŒ X | S  ¢ ‚  ç ‘ ’ 0ðñ 2 “ < ]” 

)AGoldring [4] iƒ ðe¢ÓŒ  

, D EX |  T{‚ B ² (1)pì ?T Ô p • ‚T?– ¡ , … — ˜ ™ ) (2)š › RSD ETU ^ _ ` a) (3)A" œ D  ž   M{0dz ` aX | ) (4)ÅX | Ÿ R G ¡ ¢ L k £ ¤ Mš E ¥ ) (5)#¦" X | 0‰ T§ § 4 )  ~  ç X | ’ 0â ; • ü ¡  , D E9 :¨ ë 0© ª  , D E  ` aë 0§  « Ž ARS` aü -üD , D E)  F GHIˆ ¬ ’ ~  ç ‘ X | ô p Åç ­ . ® û{² (1)   F GHI` ay G   , œ D RS  Re ^ f® ¯ RS Re ^ f@ A\?$ ¡ ,  D E) (2)A  F GHIÎ` ay G RSTUÅ ^ _ Re #F GHI …@ d9 : T ë „ ° RS` aÅ^ _ Re ` ac  y G{-) (3)   L M  E" ±   Å{  F GHI0æ « y G R S` aX | ) (4)² 1   F GHIc e³ ´  £ ¤ † OèÅ` aERSkÅ^ _ Re  £ ¤ ë µ ¢¶ T  £ ¤ EX |  TÅy G £ ¤ X | ë · ¸ § ¹ ¦) ó ¢v ø   F GHIº ë ° G¡ ¢ L (command line)¡ ¢ Ÿ\ş R G ¡ ¢ L k £ ¤ Mš ) » ¼ ½ /° E 1  , D E9  #® ¯ R S\ åˆ ? E¦" X | ‰ T§ § ¾ )

(3)

3.2    









































  F GHIT¿ 9 À Á ‘ K OÌY Ó  F GHI„ B fE° (key)‚TÅ @ Å^ #Q °õ)ÎRSA#  F GHI …Âb žÅÂb X Y {L P Âç ­ õ² (1) Re ^ f² #@ de  F GHIRe ^ f)?T $‰ TŠ‹Œ E 6  eMRS   WRe ^ TН 8 6kŒ ) (2) Âb ô p ² l Ã Ä   F G H I  Âb ô p  û

QueryValuePCreateKeyPTU SetValue h)

/ k 6 ë Âb 9 : Žˆ ? 0E8 6D E) (3) °õ² « Å Í @ de°õ, Æ )ü« RS @ d  ` a #Ç  / 8  6  ` a ° õˆ ?0E8 6¨ ¥) (4) k Q 9 :² Âb  ‘ c  û SuccessPNotfoundP T U Access deniedh)/¡ k 6k Q ë ¨ ¥ˆ ?0E8 6¨ ¥) (5) k l ‘ c ²  @ de°õÈ « Å õ) Aç ­ Š dv ø fhiÉ Š d ü I Â-…Etu € #Ç ]‹ERe ^ fPÂb ô p P°õPk Q 9 :hI Â) · E ë Š dAP Óç ­ Êk l ‘ c    A   F G H I M   [ \ å  ™ Ë k Binary X | OÌ(Ì Í % 1)™ Ë X |  üX Y ¸ —  Binary X | 7 aÉ " Î Ey Ï W þ K X Y Ðâ ë  ü)Å \ å k l ^ fP, Æ hèÅÇ È ë É  A ÍÑ õ[E› œ\fhië ‰ TŠ d $ç ­ )                       1. 109375         !!!! """" #### $$$$ % %% %

3.3 SVM  



















OCSVM

Ò „ ¢p ‹l m n oHÓOCSVMÔ¡ Î tu ° „ ¢ô p X | Õ Ö ‹× ô p km × ô p MX | žņ ‡J î ;ë  Å SVM p ‹)Af' ( tu A  , D E€ À [Ø O  , D Eb 5 6 Ù ¦B C RSD E\A$„ ¢ô p X | ÓÐ&  5 6D EX | Ô9  {tu Ú d OCSVM -…E€ † ‡]p q )

AQ  OCSVM ž " ³ ´ g 0(kernel

function)z TŠ Û )OCSVM ðñ " ³ ´ g 0

2  A  v ] ; X | 9Ü ë  s † ‡ …€   T d z ¥ ] p 9  )- é  † ‡

LinearPPolynomialPRadial BasisPSigmoidP k

Precomputed Kernel hP Âtu SÝ AÅŠ Û

¢Ó“ ’ , ‚Ä Þ “ ΀ Ì T Ž ¥ € † ‡5.2D ;#~ ¢B ¢M . ® )

3.4    

















































































SVM  













tu   RSA@ d  F GHIž Å ` a 9 : ÅU V  @ A  û T OpenKeyP

CreateKeyPCloseKey E¢` aMß à 9 :7 Ž á

#^ F GHID ^ a~  ß à 9

:× Ì  F GHI Data M ! " Ž â ¨ ¥

@ A)

 OCSVM A€ 5 6D EM† ‡  

žš á ¦ E O(dL3) [5]A…]p ` až

A‰ „ s ã X | 2 Å eM™ š á ¦ E

O(d(L+T)) Å d E€ ž  e™ š ä

  L ü€ X | å  T üs ã X |  å )æ /tu 0 < › œ€ X | ks ã X |  o › œ™ š d  [< ç

A–— OCSVM  € žš tu A5.1

D ;#$T« ¬. ® M)

4.

$

$

$

$

%

%

%

%

&

&

&

&

'

'

'

'

#(

#(

#(

#(

)

)

)

)

4.1    

























f -éT  F GHIk SVM ‘ ’ 

A J K v ø -éT€ À [ÓX | 3 4 P5 6† ‡J K k8 6r s F [Ö è OÌ) X | 3 4  - é T Registry MonitorPData

ConvertPRedundant Data Deletion 3ӆ O O

Ì)5 6† ‡€ ks ã X | ]p Ç #ˆ

j  OCSVM k Timing Module -Ê Ì)T{

E J K % ²

 

(4)

% 2 ?$ ¡fhi-é?]EX | €  À [k8 6r s [\ ]T{;9$F [\ ] pì ‰ TL Ÿ . ® kG H )

(1) € À [

A$À [ce{L † O²

(A)Registry Monitor²_ `   F GHI

` a9 :‚;My G{-T…E  X | é ¥)

(B)Data Convert²; Registry Monitor y G

-é ê X | ëì E OCSVM  n

oX | ‚; eç ­ í d¡-)

(C)Redundant Data Deletion²;ëì § 2 é…

E€ Ž á X | Þ T¾ Tj –˜ @ ™ š k€ žš )

(D)OCSVM²€ 5 6D E{5 6†

‡)

(2) r s À [

A$À [ce{L † O²

(A)OCSVM²Ar s ž;s ã X | k5 6† ‡D Ç #a) (B)Timing Module²j ë žš -#X | D î ï M2 }…s ã X | r s Ç #)

4.2   



















T{9e . ® Q † O. ® « U ¨ ¥²

Registry Monitor²Af' ( tu j 

SysInternals   ¡-Tñ Windows L M

   Regmon.exe [10] …E-éRS)Å

R S j  API Hooking (Application Program

Interface Hooking) ð ñ -dz RS#F GH

I@ d` a¨ ¥)

Data Convert²$† OT Java  -ég 0

;tu A Registry Monitor G{-F GHI

@ dG…X | ëì aT] 0ñ OCSVM -…† ‡€ ò ‘ c En o‡:X | ) Aëì § Ró ;tu éeç ­ ‰ Tí d¡-}ëEn oX | ‡:-é?]E ÓM N² (1) RS• dF GHI@ dGT Žç ­ ô I~ È ç ­ E 3.2 D õ ˆ Re ^ fPÂb ô p P ° õ Pk Q 9 :hI Â) (2) RS• dF GHI@ dGkÍ¢M N  Žç ­ ô I;F GHI@ dGë ì EOCSVM?j Mn o‡:X | )

Redundant Data Deletion²Å-ég 0A;

X | Ž â ¨ ¥‰ T¾ A~ † Otu j  J î F ö ¿ v S;X | ‰ T÷ e ‚ø Ž á  \ å ¡Ž á X | ù ú X | û ) 5 6† ‡€ ks ã X | ]p Ç #ˆ j  OCSVM -Ê Ì  SVM ±  ü [s ý þ  ' (   M libSVM [7]-…E « Å  ͱ )AX | 4 \ åtu ó ;Õ ƒ „ OCSVM M5 6€ X | b Ñy E (+1) Ó EÑy ‚C à ÔTj ]p D Îs ã X | k €  X |  Ž  † ‡ Ç # ž  /

OCSVM Šß Eë ô p X | ˆ cAX | 3  Ñ

y E (-1)ˆ ü8 6¨ ¥ Ž)

8 6 r s  \ å ˆ  OCSVM k Timing

Module O̲

OCSVM²A3 ø Ÿ. ® $† O€ 5 6

† ‡w8 6r s \ ]ˆ T OCSVM -œ D ]p a ó Š ß s ã X | k#Q  5 6† ‡}‰ TŠ‹s ã X | 8 6R )

Timing Module²$† O-é  , A

ë žš Ö [Mc ë   D E9 :Z $j ë žš Ö [- Ž€ † ‡ ‚T9Ü žš Ö [-…s ã X | Ç #)~ x  …w?;X | 9Ü ë žš Ö [-…î ï T ]‹€ ] 0› œX | oT–— OCSVM A € † ‡ž  žš Ìf)

5.

(

(

(

(

*

*

*

*

+

+

+

+

,

,

,

,

5.1      !































!

!

!

A$. ® X | Ž â ¾ –« ¬‘ c  ó t u j G Œ F GHI@ dy G;$X | .

 Redundant Data Deletion RS-‰ T4

-é¾ #Ç EI ô ç ­ b ^ X | ‚;. § 4 X | kR . § 4 X | D Ç # Tæ ã $¢4 v S‚ë c! eX |  æ  kR -r s < 0)     2. )))) **** ++++ ,,,, ---- .... //// 0000 1111 2222 A   A B   B  (KB) 2,304 513 4,551 85     65,536 14,580 129,450 2,392 (%) 99.99 99.97 100 100     <1 <1       28 <1 722 <1   13 <1 25 <1      311 <1 927 <1 ü 2 Gé ê  A ké ê  B]‹ * + A k* + B y G{-  F GHI` a X | Å* + A E[o Q RS  Ž  * + B ˆ E„  ® ¯ RS` a   Ŗo§ 2   ]‹E–o  A k–o 

B)A. § –o4 M2   A M  ì o[ w é - 2,304 KB –E 513 KBX | Ç  é ó  65,536 å–E 14,580 åEé ó  M I ]M¢A  B \ ]Å  ì o[w é - 4,551 KB –E 85 KBX | å é ó  129,450 å–E 2,392 åEé ó  Mý ]M ¢) Ç #‘ c   A \ åé ó  99.99% › E 99.97% 5 æ È › œ

(5)

0.02%  B \ åˆ ä  A 100% 9 : {› 7 a)

tu E~ x « ¬‘ c …T{. ® ²A[ o Q RS9  {* + A Q RS ô p  " \  F GHIß à 9  ⠗  èA. § –o4 2  ? –I ]M3X |

o   w o æ È Ó{› 0.02%Ô) ~ x ‘ c Z E SVM A4 Íç có ¾ Ø  õX | A. § –oM2 Ø  õü  ë ®  × Ì]p Í  ) Aë  Q RS9  {* + B 4 ° ® ¯ RSAœ D 9 :)Z $® ¯ RSŽ â  9   " \ÅX | 0 – — · é ó  ý ]M ¢Ç * + A –oÇ ú é" ‚TA æ È Í ‚ › œ) T~ x « ¬‘ c $ -ÅX | –o2 ì o[ w û͈ iƒ . OCSVM A€  5 6D EMF GHI@ dX |  žš á ¦

 E O(dL3) A…]p ` ažÅ eM™

š á ¦ E O(d(L+T))Ò  A -. ŀ  žš Eé ó  (1/4)3 Òð -4  žš  64 A™ š  Íř š  o Eé ó I ]M¢)A  B \ åŀ ž š ˆ ð Eé -4 žš  216 ™ š  o Eé ó ý ]M¢)èA« Å   SVM žc#ų ´ g 0…Š d¿ À ë ³ ´ g 0 á ¦ c! Å4 žš   ‚T« Å –ožš kƒ „ X | á ¦  _ X |  á ¦7 X | å  " ˆ 4 žš  " ) ² 1 AÍü« ¬ À M† ‡€ žš 8 ë [è « X | o " Şš ;T¡ Ì ) W Õ ~ x ‘ c #ð OCSVM 4 !  Í0 ® ð )

5.2 OCSVM " # $  %

"

"

"

#

#

#

$

$

$







%

%

%

AÌ Š ß Ítu ;9Ü 5 6† ‡J K k« Å ¨ © s ã X | ‘ c -1 " . ® )5 6† ‡ J K E …EM2 Tñ Ä AН s ã X | 5 6kŒ -éT#  -$ o† ‡5 æ  kù æ  [1]Afhiˆ ¡ † ‡R % eÌ Š ß ! &  ¡-?' R ü 3 Tx € X | ( ’ Q ô ë g 0kÌ O’ -€  5 6† ‡‘ c ņ ‡#  a u ) SE² † ‡#  * 5 æ  ]p MX | å + ƒ „ X | å     3. 3333 4444 5555 6666 7777 8888 g 0† O ƒ „ Ì † ‡#   Radial basis 0.53 99.73% linear 0.01 98.99% polynomial 0.35 65% 2 tu Š ß A¢OÌ kg 0O’ ¡ É #  …E5 6† ‡Š ß )

5.3 & ' ( ) *  ! + ,

&

&

&

'

'

'

(

(

(

)

)

)

*

*

*







!

!

!

+

+

+

,

,

,

fhi¿ À ¢¶  , « Å  * +?0 ¨ ¥O a {L  ¨ © T 1  r s  Ì< E )A€ X | G \ ]fhi; , Aù à © {Ø O Åà © R @ Å B C RS9 :{‰ Tœ D ù Q RS‚T,# ù g 0-‰ Tœ D Tæ r 0ü   , ?0 ŽD E…E- . M€ X | )T{Ò ]‹T , P* + 9  P žš 9  , #I ô ë ¨ © -D « ¬² (1)ë ž‰  , ’ wžš p MÇ â ² tu .  ,  * +MF GHI@ d Gj f' ( ð¡ / R‰ TÇ #T ЋŠ9  Œ ^ tu T¢ ,  0 ž[ 1 û X | ΀ X | T¢ , 2 ž[Îs ã X | T‘ c -¬­ tu ð¡ Œ 0: 3 ‹¡¢ ,   D E† S) (2)¢ ,  ^ * +4 5 š D EÇ â ² x  , A4 5 š  RS?0c « ‹ú û5 š  ù 6 mp3 7 $ + , ! 7 h T ì í Ò?Н ¡D E8  A~ 8 s ã X | tu T , * +5 š 9

û e  F GHI Data ÎÌs ã X | -¬­

tu 0Œ 3 ‹ ,  ù 6 7 ‹ -8 ) (3) ë  ,  ^ * +TE^ ž[² é E’ w , A * +Z ™ :;$ ž ¢m w   , j  ~ Ó ™ -   $  * +Å^ _ ` a;c y G{-)m w ,  RSk’ w , 5 69  { ë ^  A’ w , ž  žš M p?Tžš † O-‰ T3 ã [žš 8 6  ¨   Ž) (4)  ,  ^ * + < = RS@ A² A~ ¨ © tu † ª * +> % ? @ Blaster < = 9  T Blaster Ï Ð RS#R . patch  A B  Windows   Ï Ð ‚Ý Þ Å? @ < = 2 k5 6  D EŒ B tu Ð?Tj tu J   Þ C ? @ < = 2     Ž8 69 :) A 1 û ; - .  €  X | 2  t u T SVM(OCVM)† OJ î 5 6 D E† ‡1 2 ,#Q ¨ © 1 û Ms ã X | }D . SVM E „ 5 6† ‡ks ã X | -‰ TÇ #- 1 Ł

(6)

8 60€ E )ü 4 fhiAQ ¨ © Í G  s ã X | k€ X | Ç #2 8 6 A$ 8 6 ¡ k t u €  ¡  † ‡ M š 8 6 R  8 6 õ É üB ;5 6D E " ) ü4]L ¡Q ¨ © « ¬  Ž« ¬‘ c )   4. 9999 :::: ;;;; <<<< ==== >>>>  « ¬¨ © 8 6  ¨ © ¢² , D EÇ â 0.55% ¨ © F ²4 5 š D EÇ â 49.65% ¨ © 3² , :; 67.46% ¨ © I ² ? @ Blaster 29.23% TÍ« ¬ À ?j tu ?T  Š‹¢ , F D Ekë  , F  D E m 6 « 8 ¢ , AÅ D E† SR 6 7 ž8 6R E 0.55%G A tu ì ! Н  > @ Mp²èA ? @ Blaster+ = M2 Blastercq 6 \ ]F G

HIpì TH % WaŽ   HRe . t u   Å8 6R I J §  , 5 6 { × Ì8 6R Z $tu ?TŠ‹~ B ; , D EU > 8 6D E¨  ) TÍ« ¬ À ?j tu ð¡J K 0: < Š‹ Œ 4 5 6 , D E† S{T0 < ÂC  , D E8 69   Ž‚TA? @ < = × Ì8 69 :{tu  Ð?T Å × Ì8 6B ;D E r s ¡- 8 69 :@ A)

6.









-

-

-

#„ ò r s  -. û O a ¢£ < ³ ´ † ST æ Š‹¡8 6D E Ž  2 3 [K _ L z { M¢   U z   Í% & z { ¢ M N Á-_ L O B M¢ú ûá  Vista] A% & z { Í" « P ) Z $fhið¡¢£     F GHI -Н  , D EŒ 8 6¨ ¥ ŽD E8 6r s v w)¦§  , D E8 6r s Ý B  ‘ ’   F GHIk SVM -J K 8 6D E3 ‹ ) ó  A  F GHIk SVM‘ ’ ÍZ Q ‘ ’ ç tu ð¡ –o” • v S-6  < 0z { æ « ð tu ð¡J K A X | ˜ @ k€ Š¯ Í< 0)T. « ¬ ¬­ f' ( ð¡J K æ « 0: < Ö ]  , D E† S‚T < 3 ‹¡?Q 8 6 D E 9 : Tf' ( ð ¡ J K  Ž  Š ¯   Atu 0E % > @ Mp)) _ f' ( 2 “ ?0' ( v n tu ]E T{B D > ? ² (1) 5 aRS û   F GHI` aX | -D 5 a R€  : tu ' (  R Ú € X | 5 ts  k á   v S  T AR . €     , X | ͈ R " ‰ > ? )/0;á X | 5 a „ € X | Å € ¡-5 6† ‡;  É Н 0€ ; ¬ ’  , Î{D E† S) (2) û T5 æ žš Ö [Tü  , D E† S : ûtu j T  , D EU U c žš 6 7 éû ù æ ü , A¢Ö [žš  D E ¡ , D E7 R9À ; tu R -;‰ T_ L V { M¢)

7.

.

.

.

.

/

/

/

/









0

0

0

0

[1] R[q  a s hkQ þ W ¡X Y  2001)

[2] Frank Apap, Andrew Honig, Shlomo Hershkop, Eleazar Eskin, Salvatore J. Stolfo. “Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses.”In Proceedings of the Fifth International Symposium on Recent Advances in Intrusion Detection, 2002.

[3] W.H. Chen, S.H. Hsu , H.P. Shen, Application of SVM and ANN for intrusion detection, Computers Operations Research, Volume 32, Issue 10, pp. 2617-2634, 2005

[4] Tom Goldring,”User Profiling for Intrusion Detection in Windows NT”, National Security Agency, 2003.

[5] Salvatore J. Stolfo, Frank Apap, Eleazar Eskin, Katherine Heller, Shlomo Hershkop, Andrew Honig, and Krysta Svore, "A comparative Evaluation of Two Algorithms for Windows Registry Anomaly Detection". Journal of Computer Security, 2005

[6] Yanxin Wang, Johnny Wong, Andrew Miner, “Anomaly intrusion detection using one class SVM”, In Proceedings from the Fifth Annual IEEE SMC Information Assurance Workshop, 2004.

[7] Andrew W. Moore, “Support Vector Machine”,

http://www.autonlab.org/tutorials/svm15.pdf

[8] Chih-Chung Chang and Chih-Jen Lin, LIBSVM : a library for support vector machines, 2001. Software available at

http://www.csie.ntu.edu.tw/~cjlin/libsvm

[9]Piaip's Using (lib)SVM Tutorial.

http://ntu.csie.org/~piaip/svm/svm_tutorial.html

[10]SysInternals. Regmon for Windows NT/9x. Online publication, 2000. http://www.sysinternals.com/ntw2k/source/regm on.shtml [11]Windows NT Registry http://www.microsoft.com/resources/

(7)

[12]Global Market Share Statistics Website http://marketshare.hitslink.com/report.aspx?qpri d

參考文獻

相關文件

三、網際網路註冊報名登錄之球衣號碼,不得更改。球衣號碼總教練為 30 號,教練分別 為 29 號及 28 號,行政管理人員為 27 號,球員為 1 號至 22

 1932 年提出李克特量表( Likert Scale ),是一種 心理測量量表,通常用於問卷設計,為目前最受調查 研究者廣泛使用的測量方法.

檢視 檢視「 「 「 「輸出 輸出 輸出 輸出」 」 」 」視窗表示 視窗表示 視窗表示 視窗表示 程式碼沒有任何錯誤

The Model-Driven Simulation (MDS) derives performance information based on the application model by analyzing the data flow, working set, cache utilization, work- load, degree

The relationship between these extra type parameters, and the types to which they are associated, is established by parameteriz- ing the interfaces (Java generics, C#, and Eiffel)

 Evaluated deadline and cost perfor mance of various scheduling polici es under a large range of SLA cost function and

在雲中街文創聚落中營運中的「凹凸 咖啡館」是利用當時遺留下的建築群

以角色為基礎的存取控制模型給予企業組織管理上很大的彈性,但是無法滿