提出一种利用动态提取进程堆栈中的信息来寻找不定长模式的方法。
A novel method is proposed to construct variable-length patterns by using dynamically extracting information from call stack of the process.
在此基础上,以不定长模式作为基本单位构建了一个马尔可夫链模型来检测异常行为。
Then a Markov chain model is constructed based on variable-length patterns to detect abnormal behaviors.
应用推荐