Title :
An immune genetic model in rule-based state action IDS
Author :
Xu, Zhou-jun ; Sun, Ji-zhou ; Wu, Xiao-jun
Author_Institution :
Sch. of Electron. & Inf. Eng., Tianjin Univ., China
Abstract :
From the 1999 DARPA´s testing results, it is found that one of the most significant drawbacks of intrusion detection systems (IDS) is the low recognizing ratio of new attacks. As rule-base IDS can gain good detecting performance, we build a genetic immune model, which is adaptive to rule-based IDS, to improve the IDS´s detecting performance of new attacks. As one successful method, state transition (ST) analysis models penetrations as a series of state changes that lead from initial state to a target compromised state. Using this model of recomposing the ST method to solve the low recognizing ratio problem is presented in this paper. In this model, ST method can be expressed in a double DNA chains pattern. One chain is the system state chain; the other is an action chain. The double twisting chains form a state-action sequence to represent the system state transitions. In order to still gain the recognizing performance of the regular ID systems, we use STAT rules to create the initial non-self (or expert) DNA library, and newly found attacking-rules can still be added to the library. A simple host-based test is also performed to prove the effectiveness of this model.
Keywords :
genetic algorithms; knowledge based systems; security of data; double DNA chains pattern; immune genetic algorithm; intrusion detection systems; rule-based IDS; state transition analysis tool; system state chain; DNA; Flowcharts; Genetic algorithms; Humans; Immune system; Intrusion detection; Libraries; Performance gain; Postal services; Testing;
Conference_Titel :
Machine Learning and Cybernetics, 2003 International Conference on
Print_ISBN :
0-7803-8131-9
DOI :
10.1109/ICMLC.2003.1259927