DocumentCode :
2664235
Title :
Integrating Innate and Adaptive Immunity for Worm Detection
Author :
Zhang, Junmin ; Liang, Yiwen
Author_Institution :
Sch. of Comput. Sci., Wuhan Univ., Wuhan, China
fYear :
2008
fDate :
10-12 Dec. 2008
Firstpage :
645
Lastpage :
650
Abstract :
As most of existing worm detection methods have a number of significant hurdles to overcome in order to employ such actions as blocking unsecure ports, dropping potentially threatening packets, and eliminating emails carrying malicious codes, breaking communication between infected and non-infected hosts to slow down worm propagation and minimize potential damage. The most noteworthy obstacle is the high false positive rate problem. A recently developed hypothesis in immunology, the danger theory, states that our immune system responds to the presence of intruders through sensing molecules belonging to those invaders, plus signals generated by the host indicating danger and damage. Inspired by the theory, the paper proposed an artificial immune model for worm detection. The model considers the cooperation of dendritic cells (DCs) in the innate immune system and T cells in the adaptive immune system, in which system calls comprising a process generated can be viewed as antigens and the corresponding behavioral information of the system and network can be viewed as signals. The theory analysis shows that the dual detection method of DCs detecting the behavioral information caused by antigens and T cells detecting antigens can decrease false positive rate, and the model has a fast secondary response to the reinfection by the same or similar worm.
Keywords :
Internet; artificial immune systems; invasive software; adaptive immune system; antigens; artificial immune model; behavioral information detection; danger theory; dendritic cells; emails carrying malicious codes elimination; immunology; innate immune system; potential damage minimization; potentially threatening packets dropping; unsecure ports blocking; worm detection; worm propagation; Adaptive systems; Computer networks; Computer science; Computer worms; Distributed control; Event detection; Immune system; Intrusion detection; Signal generators; Signal processing; Dendritic cells (DCs); T cells; danger theory; negative selection; worm detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence for Modelling Control & Automation, 2008 International Conference on
Conference_Location :
Vienna
Print_ISBN :
978-0-7695-3514-2
Type :
conf
DOI :
10.1109/CIMCA.2008.75
Filename :
5172701
Link To Document :
بازگشت