首页 | 本学科首页   官方微博 | 高级检索  
     

基于免疫机理的网络入侵检测系统的抗体生成与检测组件
引用本文:闫巧,江勇,吴建平.基于免疫机理的网络入侵检测系统的抗体生成与检测组件[J].计算机学报,2005,28(10):1601-1607.
作者姓名:闫巧  江勇  吴建平
作者单位:[1]清华大学深圳研究生院,深圳518055 [2]清华大学计算机科学与技术系,北京100084
基金项目:本课题得到国家“九七三”重点基础研究发展规划项目(2003CB314805)、中国博士后科学基金(20040350027)和广东省自然科学基金(34308)资助.
摘    要:介绍了作者设计并实现的基于免疫机理的网络入侵检测系统的抗体生成与检测组件.作者在该组件实现中类比自然免疫系统自适应免疫的两种免疫类型提出了被动免疫抗体和包括记忆自动免疫抗体及模糊自动免疫抗体的自动免疫抗体的概念.它是结合了模糊推理系统和统计的方法,达到了改善入侵检测系统的性能的目的.该文还给出了根据收集到的网络数据包以及DARPA1999的入侵检测评估数据对基于免疫机理的网络入侵检测系统的测试实验.通过与SNORT系统以及DARPA的检测结果进行比较,证明了使用了抗体生成与检测组件的基于免疫机理的网络入侵检测系统对已知和未知攻击都有令人满意的检测率.

关 键 词:网络安全  入侵检测  人工免疫  被动免疫抗体  自动免疫抗体
收稿时间:2004-03-09
修稿时间:2004-03-092005-07-15

Antibody Generation and Antigen Detection Component in Immune -Based Network Intrusion Detection System
YAN Qiao, JIANG Yong, WU Jian-Ping.Antibody Generation and Antigen Detection Component in Immune -Based Network Intrusion Detection System[J].Chinese Journal of Computers,2005,28(10):1601-1607.
Authors:YAN Qiao  JIANG Yong  WU Jian-Ping
Affiliation:1 Graduate School at Shenzhen, Tsinghua University, Shenzhen 518055;2 Department of Computer Science and Technology, Tsinghua University, Beijing 100084
Abstract:The authors design and develop an immune-based network intrusion detection system--AINIDS, which includes a data collector component, a packet head parser and feature extraction component, antibody generation and antigen detection component, co-stimulation and report component and rule optimization component. The antibody generation and antigen detection component is the key module of AINIDS. In the component the passive immune antibodies and the automatic immune antibodies that include memory automatic immune antibodies and fuzzy automatic immune antibodies are proposed by analogy with natural immune system. The passive immune antibodies inherit available rules and can detect known intrusion rapidly. The automatic immune antibodies integrate statistic method with fuzzy reasoning system to improve the detection performance and can discover novel attacks. AINIDS is tested by the data collected from the LANs and by the data from 1999 DARPA intrusion detection evaluation data sets. Both experiments prove AINIDS that includes antibody generation and antigen detection component has good detection rate for old and new attacks.
Keywords:network security  intrusion detection  artificial immune  passive immune antibody  automatic immune antibody
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号