Netinfo Security ›› 2021, Vol. 21 ›› Issue (5): 31-38.doi: 10.3969/j.issn.1671-1122.2021.05.004

Previous Articles     Next Articles

Research on Detection Method of User Abnormal Operation Based on Linux Shell Commands

WU Chi, SHUAI Junlan, LONG Tao, YU Junqing()   

  1. Network and Computation Center, Huazhong University of Science and Technology, Wuhan, 430074, China
  • Received:2020-11-15 Online:2021-05-10 Published:2021-06-22
  • Contact: YU Junqing E-mail:yjqing@hust.edu.cn

Abstract:

Aiming at the security requirements of data center, this paper studies and designs two kinds of abnormal operation detection methods based on rule and command sequence, and realizes the abnormal operation detection system based on Linux Shell commands. In the rule-based abnormal operation detection method module, a rule base matching algorithm is designed to detect the Shell commands executed by the monitored users. In the module of abnormal operation detection method based on command sequence, the user behavior feature library is constructed with the legal user history command sequence as the training set, and the abnormal operation detection algorithm based on abnormal command sequence is used to determine whether the monitored user operation is abnormal. The experimental results show that in the university data center environment, the rule-based abnormal operation detection method has high detection efficiency, and the command sequence based abnormal operation detection method has high detection accuracy, which can meet the abnormal detection requirements of the data center for users to execute Shell commands.

Key words: Linux Shell, abnormaly detection, rule base, command sequence

CLC Number: