计算机应用 ›› 2005, Vol. 25 ›› Issue (01): 150-153.DOI: 10.3724/SP.J.1087.2005.0150

• 信息安全 • 上一篇    下一篇

基于病毒复制行为的网络免疫系统的研究

张涛,吴灏,奚琪   

  1. 信息工程大学信息工程学院
  • 出版日期:2005-01-01 发布日期:2005-01-01
  • 基金资助:

    国家863计划资助项目(2003AA146010)

Research on the network immune system based on replication behavior of the viruses

ZHANG Tao,WU Hao,XI Qi   

  1. College of Information Engineering, Information Engineering University
  • Online:2005-01-01 Published:2005-01-01

摘要: 生物体免疫系统是一个高度复杂的系统,专门来检测并消除病毒的传染。计算机安全系统同它有很多相似之处,对它们相同点的研究会对加强计算机安全提出许多方法。文中基于生物免疫系统中淋巴细胞激活的理论提出了基于病毒自我复制行为的行为特征检测模型。并对该模型的有效性进行了分析和实验。结果表明该模型可以成为一种新的尝试来针对病毒的复制行为进行检测,同时还能有效地减少在进行"自我"和"非我"的区别时出现的有害误报和无害误报问题。

关键词: 免疫系统, 计算机病毒, 自我复制, 模糊匹配

Abstract: The biological Immune System(IS) is highly complicated and aimed at detecting and removing the viruses. There’re many similarities between the computer security system and living organism’s IS. So the researches on the similarities could provide important clues about how to construct robust computer security system. Based on the theory of lymphocyte activation, a behavioral characteristic detecting model based on the self-replicating behavior of the viruses is brought forward. A validity analysis and experiment was made. The results of the experiment show that this model could become a new try to detect the viruses according to the replication behavior of the viruses. And at the same time it effectively reduces the problem of false negative and false positive in the process of distinguish between self and non-self.

Key words:  immune system, computer virus, self-replication, fuzzy match;

中图分类号: