Integrating Innate and Adaptive Immunity for Intrusion Detection
- 540 Downloads
Network Intrusion Detection Systems (NIDS) monitor a network with the aim of discerning malicious from benign activity on that network. While a wide range of approaches have met varying levels of success, most IDS’s rely on having access to a database of known attack signatures which are written by security experts. Nowadays, in order to solve problems with false positive alerts, correlation algorithms are used to add additional structure to sequences of IDS alerts. However, such techniques are of no help in discovering novel attacks or variations of known attacks, something the human immune system (HIS) is capable of doing in its own specialised domain. This paper presents a novel immune algorithm for application to an intrusion detection problem. The goal is to discover packets containing novel variations of attacks covered by an existing signature base.
KeywordsIntrusion Detection Innate Immunity Dendritic Cells
Unable to display preview. Download preview PDF.
- 3.Janeway Jr., C.A.: Approaching the Asymptote? Evolution and Revolution in Immunology. Cold Spring Harb Symp. Quant. Biol. 54 (Pt 1), 1–13 (1989)Google Scholar
- 7.Ning, P., Xu, D., Healey, C.G., Amant, R.S.: Building Attack Scenarios through Integration of Complementary Alert Methods. In: Proceedings of the 11th Annual Network and Distributed System Security Symposium (2004)Google Scholar
- 10.Twycross, J., Aickelin, U.: libtissue - implementing innate immunity. In: Proceedings of the Congress on Evolution Computation (2006)Google Scholar
- 11.Washington University FTP Server, http://www.wu-ftpd.org/
- 12.Mathias, K., Whitley, D.: Transforming the Search Space with Gray Coding. In: IEEE Conf. on Evolutionary Computation, vol. 1, pp. 513–518 (1994)Google Scholar
- 13.Balthrop, J., Esponda, F., Forrest, S., Glickman, M.: Coverage and Generalization in an Artificial Immune System. In: Genetic and Evolutionary Computation Conference (GECCO) (2002)Google Scholar
- 14.Tedesco, G.: Firestorm Network Intrusion Detection System, http://www.scara-manga.co.uk/firestorm/
- 15.Roesch, M.: Snort Network Intrusion Detection System, http://www.snort.org/
- 16.Berkeley Labs Internet Traffic Archive Data Set: LBNL-FTP-PKT, http://www-nrg.ee.lbl.gov/LBNL-FTP-PKT.html
- 17.Yegneswaran, V., Giffin, J.T., Barford, P., Jha, S.: An Architecture for Generating Semantics-Aware Signatures. In: Proceedings of USENIX Security Conference (2005)Google Scholar