Towards Building a Masquerade Detection Method Based on User File System Navigation

Towards Building a Masquerade Detection Method Based on User File System Navigation
复制标题

构建基于用户文件系统导航的伪装检测方法

DOI:
10.1007/978-3-642-25324-9_15
复制
发表时间:
2011
期刊:
International Journal of Computer Applications
影响因子:
--
通讯作者:
Erika Sánchez
Erika Sánchez
中科院分区:
--
文献类型:
--
作者:
Benito Camiña;R. Monroy;L. Trejo;Erika Sánchez

文献摘要

被引文献

相似文献

鉴于信息是一种极其宝贵的资产,及时检测一个人的计算机(会话)是否被伪装者非法占用至关重要。伪装检测已经被积极研究了十多年,特别是在Schonlau小组的开创性工作之后,他们建议,为了分析用户,应该对她将进入UNIX会话的命令的历史进行建模。Schonlau的小组已经产生了一个伪装数据集,它已经成为比较伪装检测方法的标准。然而,这些方法的性能并不是决定性的,因此,对伪装检测的研究已经求助于其他信息来源来分析用户行为。在本文中,我们将展示如何建立一个准确的用户配置文件,通过查看用户如何构建自己的文件系统,以及她如何导航这样的结构。虽然是初步的,但我们的结果是令人鼓舞的,并提出了一些新方法可以构建的方法。
Given that information is an extremely valuable asset, it is vital to timely detect whether one's computer (session) is being illegally seized by a masquerader. Masquerade detection has been actively studied for more than a decade, especially after the seminal work of Schonlau's group, who suggested that, to profile a user, one should model the history of the commands she would enter into a UNIX session. Schonlau's group have yielded a masquerade dataset, which has been the standard for comparing masquerade detection methods. However, the performance of these methods is not conclusive, and, as a result, research on masquerade detection has resorted to other sources of information for profiling user behaviour. In this paper, we show how to build an accurate user profile by looking into how the user structures her own file system and how she navigates such structure. While preliminary, our results are encouraging and suggest a number of ways in which new methods can be constructed.