首页> 美国政府科技报告 >Using Sequence Analysis to Perform Application-Based Anomaly Detection Within an Artificial Immune System Framework
【24h】

Using Sequence Analysis to Perform Application-Based Anomaly Detection Within an Artificial Immune System Framework

机译:使用序列分析在人工免疫系统框架内执行基于应用程序的异常检测

获取原文

摘要

The Air Force and other Department of Defense (DoD) computer systems typically rely on traditional signature-based network IDSs to detect various types of attempted or successful attacks. Signature-based methods are limited to detecting known attacks or similar variants; anomaly-based systems, by contrast, alert on behaviors previously unseen. The development of an effective anomaly- detecting, application based IDS would increase the Air Force's ability to ward off attacks that are not detected by signature-based network IDSs, thus strengthening the layered defenses necessary to acquire and maintain safe, secure communication capability. This system follows the Artificial Immune System (AIS) framework, which relies on a sense of 'self', or normal system states to determine potentially dangerous abnormalities ('non self'). A method for anomaly detection is introduced in which 'self' is defined by sequences of events that define an application's execution path. A set of antibodies that act as sequence 'detectors' are developed and used to attempt to identify modified data within a synthetic test set.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号