...
首页> 外文期刊>International Journal of Knowledge-Based in Intelligent Engineering Systems >Towards an immunity-based anomaly detection system for network traffic
【24h】

Towards an immunity-based anomaly detection system for network traffic

机译:迈向基于抗扰性的网络流量异常检测系统

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This paper proposes an immunity-based anomaly detection system for network traffic. The system is inspired by the specificity and diversity of the immune system; the system has a user-specific agent for every user, and diverse agents make a decision whether network traffic is normal or abnormal. The system makes use of multiple user profiles, which account for normal user traffic, while conventional anomaly detections have used only the single user profile. The use of multiple profiles leads to an improvement in detection accuracy. In addition, this paper proposes an evaluation framework for the immunity-based anomaly detection system. The evaluation framework is capable of evaluating the differences in detection accuracy between internal and external anomalies. In experiments, the immunity-based method outperformed the conventional method. For internal masquerader detection, the average false acceptance rate was 11.21% with no false alarms. For virus detection, four random-scanning worms and the simulated metaserver worm were detected with no false acceptances and no false alarms, while a simulated passive worm was successfully detected on some of accounts.
机译:本文提出了一种基于抗扰度的网络流量异常检测系统。该系统的灵感来自于免疫系统的特异性和多样性。系统为每个用户都有一个特定于用户的代理,并且各种代理会决定网络流量是正常还是异常。该系统利用多个用户配置文件,这些用户配置文件负责正常的用户流量,而常规的异常检测仅使用单个用户配置文件。多个配置文件的使用导致检测精度的提高。此外,本文提出了基于免疫的异常检测系统的评估框架。评估框架能够评估内部和外部异常之间的检测准确性差异。在实验中,基于免疫的方法优于常规方法。对于内部伪装者检测,平均错误接受率为11.21%,没有错误警报。对于病毒检测,检测到了四个随机扫描蠕虫和模拟的metaserver蠕虫,没有错误接受和虚假警报,而在某些帐户上成功检测到了模拟的被动蠕虫。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号