The Method of Classified Danger Sensed for Windows Process Intrusion Detection

被引:0
作者
Xu, Fei [1 ]
Tan, Chengyu [1 ]
Zheng, Yi [1 ]
Geng, Ming [1 ]
机构
[1] Wuhan Univ, Sch Comp Sci, Wuhan 430072, Peoples R China
来源
ICMECG: 2009 INTERNATIONAL CONFERENCE ON MANAGEMENT OF E-COMMERCE AND E-GOVERNMENT, PROCEEDINGS | 2009年
关键词
Danger Sensed; Artificial Immune System; Intrusion Detection; Information Security;
D O I
10.1109/ICMeCG.2009.72
中图分类号
F [经济];
学科分类号
02 ;
摘要
Once the computer system is intruded, the change from normal to abnormal is a gradual procedure. Setting up a calculating model based on Danger Theory for danger signal during the procedure will improve the accuracy and efficiency of Artificial Immune System (AIS) greatly. In this paper, the method of classified danger sensed (MCDS) for Windows process intrusion detection based on Danger Theory is proposed. This method divides the process's behavior parameters into two types: numeric and non-numeric types, using the function's difference and correlation coefficient to analyze the rule and relevance of numeric parameters' change, and evaluating the degree of danger of non-numeric parameters by analyzing the danger level and Time Relationship(TR) of data. Based on these methods, we establish calculating models of numeric and non-numeric danger signals separately, finally give the definition and calculating method of "Danger Degree".
引用
收藏
页码:469 / 472
页数:4
相关论文
共 8 条
[1]  
Aickelin U, 2003, LECT NOTES COMPUT SC, V2787, P147
[2]  
Aickelin U., 2002, 1 INT C AIS, P141
[3]  
Forrest S., 1996, P 1996 IEEE S COMP S
[4]   How do we evaluate artificial immune systems? [J].
Garrett, SM .
EVOLUTIONARY COMPUTATION, 2005, 13 (02) :145-177
[5]  
Greensmith J, 2008, LECT NOTES COMPUT SC, V5132, P291, DOI 10.1007/978-3-540-85072-4_26
[6]   Dendritic cells for anomaly detection [J].
Greensmith, Julie ;
Twycross, Jamie ;
Aickelin, Uwe .
2006 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1-6, 2006, :664-+
[7]  
KRIZHANOVSKY A, 2007, 2 INT C AV REL SEC A
[8]  
YANG H, 2006, COMPUTER ENG APPL, P34