Risk Evaluation for Host System Based on Theory of Evidence


Bring forwards a new approach to evaluate the secure level for a host system. Kernel files of OS is frangible against intruders and virus, we can log suspicious events that access the kernel, and the threaten level of each event can be defined. By mining and analyzing the data in log, using the theory of evidence, we can calculate the risk level for the whole host system. On the base of the evaluation result, the administrator can decide to enhance or lower the host defense level.

