节点文献

基于人工免疫的网络入侵检测算法研究

The Research on Network Intrusion Detection Algorithm Based on Artificial Immune

【作者】 路秋静

【导师】 叶吉祥;

【作者基本信息】 长沙理工大学 , 计算机应用技术, 2005, 硕士

【摘要】 免疫系统和入侵检测系统要解决的问题都可以被描述为识别“自我”和“非自我”,并将“非自我”消除的问题。免疫机制可以为改善计算机的安全提供借鉴, 通过对自然免疫系统的模拟研究, 可能会使计算机安全系统获得许多理想的特性。基于免疫的入侵检测利用生物免疫系统的原理、规则与机制来实现对入侵行为的检测和反应, 其目的就是利用免疫系统的免疫原理、体系结构以及从中抽象提取的有关算法来更好地解决网络入侵检测中的相关问题。 本文首先对网络安全、生物免疫系统、入侵检测以及基于人工免疫的网络入侵检测进行分析研究。在此基础上, 对现有的基于人工免疫的网络入侵检测算法进行分析比较, 针对线性时间检测器生成算法的不足作了改进。本文的主要工作如下: (1) 分析了网络安全、入侵检测技术、基于免疫的网络入侵检测。(2) 研究了生物免疫系统。包括免疫应答、特异识别、自体耐受、克隆选择、阴性选择、自体与非自体识别等免疫系统机制, 免疫系统的组成结构,免疫细胞以及免疫系统的特征。(3) 分析探讨了基于人工免疫的网络入侵检测理论。包括self 集的定义, 生成规则, Hamming 匹配规则、r 连续位匹配规则、r -chunks匹配规则,负检测模式以及可能影响系统性能的一些因素等。(4)在对网络入侵进行分析以及对现有的基于人工免疫的网络入侵检测算法进行分析比较的基础上, 针对线性时间检测器生成算法生成的检测器存在冗余,并且其时间和空间代价与r 成指数关系,算法开销受r的影响较大的不足, 对该算法进行了改进。针对广播局域网, 对self 集的定义进行了讨论分析, 在算法中考虑了检测器的生命期问题, 给出了改进算法的框架以及描述。通过实验对算法的性能进行验证, 并通过实验验证了改进算法的有效性。最后对整个研究工作进行了总结, 并针对目前的情况指出了下一步工作的研究方向。

【Abstract】 The problem that the intrusion detection system and the immune system need to solve can be described as recognizing self and non-self,and eliminating non-self.The immune mechanism can use for reference for improving computer security.By researching natural immune system simulated,probably,the computer security system can get many ideal characteristic.The intrusion detection based on immune use the principle,rule and mechanism of biologic immune system to realize the detection and response of intrusion action.The purpose is to use the principle,system,algorithm which abstracted from immune system to solve the problem of network intrusion detection better. The thesis analyzes and researches the network security,the biologic immune system,intrusion detection and the network intrusion detection based on artificial immune firstly.Then it analyzes and compares the existing network intrusion detection algorithm based on artificial immune,and improves the linear time detector generating algorithm for the deficiency.The primary works of the paper are as follows: (1)The thesis analyzes the network security,technology of intrusion detection,network intrusion detection based on immune. (2)The thesis researches the biologic immune system.It includes the immune mechanism,such as immune response,specific recognition,self tolerance,clone selection,negative selection,self and non-self recognition.Besides this,it includes the structure of immune system,immunocyte and the character of immune system. (3)The thesis analyzes and discusses the network intrusion detection theory based on artificial immune.It includes the definition of self set,generation rule,Hamming matching rule,r -contiguous bit matching rule, r -chunks matching rule,negative detection model and factors which may affect the performance of system. (4)The thesis analyzes the network intrusion and existing network intrusion detection algorithm based on artificial immune.Based on the analyse,the detectors generated by the linear time detector generating algorithm are redundant,the cost of time and space of the algorithm are exponential in r ,and the cost of algorithm is affected more by r ,so the thesis improves the linear time detector generating algorithm.For broadcast LAN,the thesis discusses and analyzes the definition of self set.And considers the problem of life-cycle of detectors in the algorithm,gives the framework and description of the algorithm improved.The performance of algorithm and the validity of the algorithm improved is verified by experiment. At last,the thesis summarizes the whole research work,and points out the research direction of further work based on the present situation.

  • 【分类号】TP393.08
  • 【被引频次】5
  • 【下载频次】357
节点文献中: