A Distributed Intrusion Detection System Based on Windows Registry
-
Graphical Abstract
-
Abstract
A distributed intrusion detection system architecture based on Windows registry is presented. The advantage of regarding Windows registry as the analysis data source and the impact of (vicious) action to registry are discussed. The data model of RIDS information source, the algorithm of intrusion analysis and the composition of sensor, inspector and data warehouse are introduced. This research will enrich the detection methods of HIDS.
-
-