Windows Native API oriented intrusion prevention model
Luo Zhan-cheng · Computer Engineering and Applications Journal · 2010
To improve the detection rate,ability of real-time detecting and intelligence of the intrusion prevention system on the Windows operating system,this paper introduces the embedded assembly language to simplify the monitoring of Windows Native API,and divides the data set into a table of independent variable-length patterns,and applies rough set theory to reduce the size of each pattern.With this method,a prevention model is built on short core API sequence and used to detect call sequence of sendmail program.A series of experiments show that this model's detection rate reaches to 96.08%,and false alarm rate falls to 1.93%.Compared with other detection models,the result demonstrates that this model has better performance on detection efficiency,ability of real-time detecting and intelligence.