File Monitoring Model Based on IRP Feature Sequence

FAN Xue-bin,PANG Jian-min,ZHANG Yi-chi,YOU Chao
DOI: https://doi.org/10.3969/j.issn.1671-0673.2012.04.024
2012-01-01
Abstract:With the extensive application of information technology,key organizations pay increasing attention to the protection of sensitive or confidential files.But existing monitoring techniques can hardly find harmful file operations.After the analysis of the intermediate driver,a file monitoring model based on the IRP feature sequence is proposed.With this model,key issues such as the asynchronous extraction of IRP feature information,sequence tracking and operation judging can be solved effectively,which means improved file monitoring coverage and judgment accuracy.Comparative experiments demonstrate the validity and accuracy of the proposed method.
What problem does this paper attempt to address?