• DocumentCode
    2694439
  • Title

    Extended thymus action for improving response of AIS based NID system against malicious traffic

  • Author

    Shafiq, M. Zubair ; Kiani, Mehrin ; Hashmi, Bisma ; Farooq, Muddassar

  • Author_Institution
    Nat. Univ. of Sci. & Technol., Rawaplindi
  • fYear
    2007
  • fDate
    25-28 Sept. 2007
  • Firstpage
    3369
  • Lastpage
    3376
  • Abstract
    Artificial immune systems (AISs) are being increasingly utilized to develop network intrusion detection (NID) systems. The fundamental reason for their success in NID is their ability to learn normal behavior of a network system and then differentiate it from an anomalous behavior. As a result, they can detect a majority of innovative attacks. In comparison, classical signature based systems fail to detect innovative attacks. Light Weight Intrusion Detection System (LISYS) provides the basic framework for AIS based NID systems. This framework has been improved incrementally, including incorporation of thymus action, since it was first developed. In this paper, we have extended the basic thymus action model, which provides immature detectors with multiple chances to develop tolerization to normal. However, AIS is prone to successful attacks by malicious traffic which appears similar to the normal traffic. This results in high number of false positives. In this paper, we present a mathematical model of malicious traffic for TCP-SYN flood based distributed denial of services (DDoS) attacks. This model is used to generate different sets of malicious traffic. These sets are used for performance comparison of the proposed extended thymus action with the simple thymus action model. The results of our experiments demonstrate that the extended model has significantly reduced the number of false positives.
  • Keywords
    artificial immune systems; security of data; artificial immune systems; distributed denial of services attacks; extended thymus action; light weight intrusion detection system; malicious traffic; network intrusion detection; network system; Artificial immune systems; Detectors; Floods; Intrusion detection; Law; Legal factors; Libraries; Mathematical model; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Evolutionary Computation, 2007. CEC 2007. IEEE Congress on
  • Conference_Location
    Singapore
  • Print_ISBN
    978-1-4244-1339-3
  • Electronic_ISBN
    978-1-4244-1340-9
  • Type

    conf

  • DOI
    10.1109/CEC.2007.4424907
  • Filename
    4424907