| 10.14489/vkit.2019.05.pp.038-043 |
|
DOI: 10.14489/vkit.2019.05.pp.038-043 Ивкин А. Н., Бурлаков М. Е. Аннотация. Рассмотрена статистическая модель системы обнаружения вторжения, основанная на искусственной иммунной системе, наборы детекторов в модели выбираются на основе заголовков пакетов. Объединены теория негативной селекции и правила машинного обучения с целью предложить новую систему обнаружения вторжения. Во время тестирования предложенной модели используются наборы данных DARPA1999, модель показывает хорошую производительность по сравнению с предыдущими моделями. Ключевые слова: искусственная иммунная система; система обнаружения вторжения; негативная селекция; машинное обучение.
Ivkin A. N., Burlakov M. E. Abstract. The paper is devoted to the crucial problem of computer security. Computer security involves protecting computers and networks from malware, hackers and other threats while maintaining privacy on the Internet and on physical systems and networks. Today, the interest in artificial immune systems has increased many times, because immune system solves a large number of problems in the field of computer security. Intrusion detection is the process of monitoring the events occurring in your network and analyzing them for signs of possible incidents, violations, or imminent threats to your security policies. These security measures are available as Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), which become part of your network to detect and stop potential incidents. The paper is aimed to show a statistical model of an IDS based on an artificial immune system, with the detector sets chosen based on packet headers. For correct operation of IDS, a deterministic set of operating parameters is required. Only header values are used to study the anomalous behavior of packets during transmission in any TCP / IP network traffic. Based on the test results, methods for improving the IDS have been proposed and implemented. The article analyzing the detection results in network and host models. The paper deals with negative selection theory and machine learning rules. The theory of negative selection is one of the most important theories of artificial immune systems. In the negative selection module, instead of using only the normal profile, to separate and classify the packages into two different classes, an additional check of each package is performed using expert rules created earlier on the basis of the normal profile table. Thus, the package goes through more stages, in order to specify whether the package is anomalous. As a result, the frequency of false positives is significantly reduced, and the frequency of detection increases. Generate detectors, a set of basic rules has been developed, using data analysis and machine learning software, and then new detectors were generated and detailed, inside the negative selection module. After testing the proposed model, using the DARPA1999 data set, the model showed good performance compared to previous models. Keywords: Artificial immune system; Intrusion detection system; Negative selection; Machine learning.
РусА. Н. Ивкин, М. Е. Бурлаков (Самарский национальный исследовательский университет им. академика С. П. Королева, Самара, Россия) E-mail: Этот e-mail адрес защищен от спам-ботов, для его просмотра у Вас должен быть включен Javascript EngA. N. Ivkin, M. E. Burlakov (Samara National Research University, Samara, Russia) E-mail: Этот e-mail адрес защищен от спам-ботов, для его просмотра у Вас должен быть включен Javascript
Рус1. Shamsuddin S. B., Woodward M. E. Modeling Protocol Based Packet Header Anomaly Detector for Network and Host Intrusion Detection Systems // Proc. of the 6th Intern. Conf. on Cryptology and Network Security (CANS’07). 2007. P. 209 – 227. Eng1. Solahuddin B. Shamsuddin, Michael E. Woodward. (2007). Modeling Protocol Based Packet Header Anomaly Detector for Network and Host Intrusion Detection Systems (Department of Computing, School of Informatics University of Bradford, United Kingdom) January.
РусСтатью можно приобрести в электронном виде (PDF формат). DOI: 10.14489/vkit.2019.05.pp.038-043 Скопируйте DOI статьи и перейдите по ссылке https://id-spektr.ru/product/pokupka-elektronnoy-stati-iz-zhurnala-vestnik-kompyuternyh-i-informatsionnyh-tehnologiy В комментарии к заказу обязательно укажите DOI статьи. .
EngThis article is available in electronic format (PDF). DOI: 10.14489/vkit.2019.05.pp.038-043 Copy the article DOI and follow the link https://id-spektr.ru/product/pokupka-elektronnoy-stati-iz-zhurnala-vestnik-kompyuternyh-i-informatsionnyh-tehnologiy Please specify the article DOI in the order comments.
.
|
Архив номеров
Разработка концепции и создание сайта - ООО «Издательский дом «СПЕКТР»