发明名称 A VMM-BASED INTRUSION DETECTION SYSTEM
摘要 <p>An intrusion detection system collects architectural level events from a Virtual Machine Monitor where the collected events represent operation of a corresponding Virtual Machine. The events are consolidated into features that are compared with features from a known normal operating system. If an amount of any differences between the collected features and the normal features exceeds a threshold value, a compromised Virtual Machine may be indicated. The comparison thresholds are determined by training on normal and abnormal systems and analyzing the collected events with machine learning algorithms to arrive at a model of normal operation.</p>
申请公布号 WO2009097610(A1) 申请公布日期 2009.08.06
申请号 WO2009US32858 申请日期 2009.02.02
申请人 NORTHEASTERN UNIVERSITY;MOFFIE, MICHA;KAELI, DAVID;COHEN, AVIRAM;ASLAM, JAVED;ALSHAWABKEH, MALAK;DY, JENNIFER;AZMANDIAN, FATEMEH 发明人 MOFFIE, MICHA;KAELI, DAVID;COHEN, AVIRAM;ASLAM, JAVED;ALSHAWABKEH, MALAK;DY, JENNIFER;AZMANDIAN, FATEMEH
分类号 G06F15/18 主分类号 G06F15/18
代理机构 代理人
主权项
地址