An immunology-inspired multi-engine anomaly detection system with hybrid particle swarm optimisations

An immunology-inspired multi-engine anomaly detection system with hybrid particle swarm optimisations
复制标题

DOI:
10.1109/fuzz-ieee.2012.6251241
复制
发表时间:
2012-06
期刊:
2012 IEEE International Conference on Fuzzy Systems
影响因子:
--
通讯作者:
F. Jiang;Sai Ho Ling;Kit Yan Chan;Z. Chaczko;Frank H. F. Leung;M. Frater
F. Jiang;Sai Ho Ling;Kit Yan Chan;Z. Chaczko;Frank H. F. Leung;M. Frater
中科院分区:
其他
文献类型:
--
作者:
F. Jiang;Sai Ho Ling;Kit Yan Chan;Z. Chaczko;Frank H. F. Leung;M. Frater

文献摘要

被引文献

相似文献

本文提出了多检测引擎和多层次入侵检测机制,以增强计算机安全。其原理是协调来自每个单引擎入侵警报系统的结果,该系统与多层分布式面向服务的结构无缝集成。提出了一种改进的隐马尔可夫模型(HMM),用于检测引擎,能够基于免疫学的自我/非自我判别。系统调用的正常和异常行为的分类将通过HPSOWM调整的高级模糊推理过程进一步检查。针对一个来自公共领域的真实的基准数据集,我们的实验结果表明,该方案可以大大缩短HMM的训练时间,并显著降低误报率。所提出的HPSOWM特别适用于未知行为和恶意攻击的有效分类。
In this paper, multiple detection engines with multi-layered intrusion detection mechanisms are proposed for enhancing computer security. The principle is to coordinate the results from each single-engine intrusion alert system, which seamlessly integrates with a multiple layered distributed service-oriented structure. An improved hidden Markov model (HMM) is created for the detection engine which is capable of the immunology-based self/nonself discrimination. The classifications of normal and abnormal behaviours of system calls are further examined by an advanced fuzzy-based inference process tuned by HPSOWM. Considering a real benchmark dataset from the public domain, our experimental results show that the proposed scheme can greatly shorten the training time of HMM and significantly reduce the false positive rate. The proposed HPSOWM works especially well for the efficient classification of unknown behaviors and malicious attacks.