• DocumentCode
    3006887
  • Title

    Multi-layer Intrusion Detection and Defence Mechanisms Based on Immunity

  • Author

    Ma, Zhanfei ; Zheng, Xuefeng

  • Author_Institution
    Sch. of Inf. Eng., Univ. of Sci. & Technol., Beijing
  • fYear
    2008
  • fDate
    25-26 Sept. 2008
  • Firstpage
    281
  • Lastpage
    284
  • Abstract
    Recently network intrusion detection is one of the hottest research topics. Existing network-based Intrusion Detection System (IDS) has drawbacks in many aspects, among of which the two outstanding problems are the high ratio of false alarms and the lack of self-adaptation. The powerful information processing capabilities of the biological immune system, such as feature extraction, pattern recognition, learning, memory, and its distributive multi-layer defence mechanisms provide rich metaphors for designing a computer immune defence system. In this approach, the authors propose a novel multi-layer defence mechanisms based on immunity, which is capable of detecting and identifying both known and unknown intrusions, elaborating a specialized response measure. Besides that, the proposed defence mechanisms have the same learning and adaptive capability of the biological immune system, and so it is able to monitor networked computer´s activities at different levels, and to improve its response under subsequent exposures to the same attack. This on-going research effort is not to mimic simply the immunology characteristics but to explore and learn valuable lessons useful for self-adaptive immune intrusion prevention systems.
  • Keywords
    adaptive systems; computer networks; learning (artificial intelligence); learning systems; monitoring; security of data; telecommunication computing; telecommunication security; adaptive learning system; biological immune system; computer immune defence mechanism; computer network activity monitoring; multilayer network intrusion detection system; self-adaptive immune intrusion prevention system; Biology computing; Computer networks; Computer security; Computerized monitoring; Data security; Immune system; Intrusion detection; Pathogens; Pattern recognition; Protection; Biological immune system; Computer immune system; Immunology; Intrusion detection system; Multi-layer defence mechanism; Network security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Genetic and Evolutionary Computing, 2008. WGEC '08. Second International Conference on
  • Conference_Location
    Hubei
  • Print_ISBN
    978-0-7695-3334-6
  • Type

    conf

  • DOI
    10.1109/WGEC.2008.56
  • Filename
    4637445