Anomaly detection in TCP/IP networks using immune systems paradigm

被引:20
作者
Seredynski, Franciszek
Bouvry, Pascal
机构
[1] Polish Japanese Inst Informat Technol, PL-02008 Warsaw, Poland
[2] Polish Acad Sci, Inst Comp Sci, PL-01237 Warsaw, Poland
[3] Luxembourg Univ, Fac Sci Technol & Commun, L-1359 Luxembourg, Kirchberg, Luxembourg
关键词
artificial immune systems; anomaly detection; detectors generation; traffic data coding; TCP/IP protocols;
D O I
10.1016/j.comcom.2006.08.016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The paper presents an architecture of an anomaly detection system based on the paradigm of artificial immune systems (AISs). Incoming network traffic data are considered by the system as signatures of potential attackers by mapping them into antigens of AISs either using some parameters of network traffic or headers of selected TCP/IP protocols. A number of methods of generation of antibodies (anomaly detectors) were implemented. The way of anomaly detection depends on the method of antibodies generation. The paper presents results of an experimental study performed with use of real data and shows how the performance of the anomaly detection system depends on traffic data coding and methods of generation of detectors. (c) 2006 Elsevier B.V. All rights reserved.
引用
收藏
页码:740 / 749
页数:10
相关论文
共 22 条
  • [1] AGRAWAL R, 2000, RC21719 IBM
  • [2] AXELSSON S, 2004, SECURITY PROTECTION, P229
  • [3] Bouzida Y, 2004, INT FED INFO PROC, V147, P241
  • [4] Dasgupta D, 1998, IEEE SYS MAN CYBERN, P3816, DOI 10.1109/ICSMC.1998.726682
  • [5] DASGUPTA D, 2000, IEEE T EVOLUTIONARY, V6, P281
  • [6] Dasgupta D., 1999, OVERVIEW ARTIFICIAL, P3
  • [7] Learning and optimization using the clonal selection principle
    de Castro, LN
    Von Zuben, FJ
    [J]. IEEE TRANSACTIONS ON EVOLUTIONARY COMPUTATION, 2002, 6 (03) : 239 - 251
  • [8] An intrusion detection system using ideas from the immune system
    de Paula, FS
    de Castro, LN
    de Geus, PL
    [J]. CEC2004: PROCEEDINGS OF THE 2004 CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1 AND 2, 2004, : 1059 - 1066
  • [9] Dozier G, 2004, IEEE C EVOL COMPUTAT, P111
  • [10] Eskin E., 2000, P 17 INT C MACH LEAR, P255, DOI DOI 10.1109/ICCSA.2008.70