Windows Host Intrusion Detection Experimental System
Xingyu Wang · Jisuanji gongcheng · 2006
A kind of intrusion detection experimental system on the widely used Windows platform is put forward. On the basis of a thorough analysis of Windows’ security properties, 18 variables are suggested to be extracted as intrusion features from Windows’ security log, system log, performance log, file integrity check, the changes of registry keys et al, and then support vector machines are used as intrusion detector to find out all sorts of intrusions. The experiment results demonstrate that the extracted features are reasonable selected and the detection method is effective.