计算机应用 ›› 2012, Vol. 32 ›› Issue (06): 1627-1631.DOI: 10.3724/SP.J.1087.2012.01627

• 信息安全 • 上一篇    下一篇

改进的人工免疫入侵检测模型

王波,刘久君   

  1. 重庆大学 计算机学院,重庆 400044
  • 收稿日期:2011-11-25 修回日期:2012-01-24 发布日期:2012-06-04 出版日期:2012-06-01
  • 通讯作者: 刘久君
  • 作者简介:王波(1960-),男,重庆人,副教授,主要研究方向:网络安全、系统集成;〓刘久君(1985-),男,四川阆中人,硕士研究生,主要研究方向:网络安全。

Improved artificial immune intrusion detection model

WANG Bo,LIU Jiu-jun   

  1. College of Computer Science, Chongqing University, Chongqing 400044, China
  • Received:2011-11-25 Revised:2012-01-24 Online:2012-06-04 Published:2012-06-01
  • Contact: LIU Jiu-jun

摘要: 针对现有的人工免疫入侵检测系统存在的缺陷,在Hofmeyr的分布式人工免疫系统(ARTIS)基础上,提出了改进的人工免疫入侵检测模型。在改进模型中,用协议分析技术对免疫模块进行协同刺激,以提高记忆检测器和成熟检测器的质量,并降低检测器的规模;通过按协议生成和组织检测器,解决传统人工免疫系统检测效率低下的问题;采用基于权值的r-连续位匹配规则提高抗体和抗原匹配的准确度;同时协同刺激模块也能够在发生风暴型攻击时自动生成动态防火墙过滤规则,以提高在发生大规模攻击情况下的性能。最后,使用MIT Lincoln实验室的DARPA数据集对改进模型和ARTIS模型进行了模拟测试及对比分析,验证了所提模型的可行性和有效性。

关键词: 入侵检测, 人工免疫, 协同刺激, 协议分析

Abstract: An improved artificial immune intrusion detection model is proposed based on ARTIS(Artificial Immune System)--a distributed intrusion detection model proposed by Hofmeyr. It aims to overcome defects of the existing artificial immune IDS. To improve the quality and reduce the scale of memory and mature detector, the improved model uses the protocol analysis technology to make co-stimulation of the immune module. The protocols are taken into account while generating and organizing detectors, so the inefficiency of traditional AIS can be covered. Weight based r-continuous matching rules are taken to improve matching accuracy of the antibody-antigen reactions. Meanwhile, the co-stimulation module can automatically generate dynamic filter rules for firewall when Flood attack occurs. Finally, we have a simulation test and comparative analysis on improved model and ARTIS model by using DARPA data sets owned by MIT Lincoln lab and the results evaluate the feasibility and effectiveness of our improved model.

Key words: intrusion detection, artificial immune, costimulation, protocol analysis