多级免疫检测器集在分布式入侵检测中的应用
Application of Multi-Level Immune Detector Set to Distributed Intrusion Detection
-
摘要: 为了提高入侵检测系统的网络环境适应能力,提出了一种基于多级免疫检测器集的分布式入侵检测模型。该模型由检测主机、检测子网和中心服务器组成,将入侵检测系统部署在网络的各检测主机中,检测子网具有与上层入侵检测网络相同的特征,中心服务器负责为检测主机和子网提供支持。通过模拟生物免疫系统的免疫细胞,检测主机的免疫检测器进行了学习和进化,该模型利用二级免疫检测器集机制,协同中心服务器的疫苗接收和种痘操作,减少了检测器的数量和提高了检测器的检测能力。Abstract: To improve the network environment adaptation ability of intrusion detection, a distributed intrusion detection model based on multi-level immune detector set is presented. The proposed model consists of detection hosts, detection sub-networks and central detection server. Intrusion Detection System (IDS) is deployed in detection hosts. Detection sub-networks have the same features of their superior intrusion detection network. Central detection server provides supports to detect hosts and sub-networks. Through simulating immune cell in biological immune system, immune detectors in detection host learn and evolve. Proposed model utilizes second-level detector set mechanism and cooperates with central detection server operation of vaccines reception and vaccination to decrease the size of detectors and improve the performance of detection.