• DocumentCode
    2664235
  • Title

    Integrating Innate and Adaptive Immunity for Worm Detection

  • Author

    Zhang, Junmin ; Liang, Yiwen

  • Author_Institution
    Sch. of Comput. Sci., Wuhan Univ., Wuhan, China
  • fYear
    2008
  • fDate
    10-12 Dec. 2008
  • Firstpage
    645
  • Lastpage
    650
  • Abstract
    As most of existing worm detection methods have a number of significant hurdles to overcome in order to employ such actions as blocking unsecure ports, dropping potentially threatening packets, and eliminating emails carrying malicious codes, breaking communication between infected and non-infected hosts to slow down worm propagation and minimize potential damage. The most noteworthy obstacle is the high false positive rate problem. A recently developed hypothesis in immunology, the danger theory, states that our immune system responds to the presence of intruders through sensing molecules belonging to those invaders, plus signals generated by the host indicating danger and damage. Inspired by the theory, the paper proposed an artificial immune model for worm detection. The model considers the cooperation of dendritic cells (DCs) in the innate immune system and T cells in the adaptive immune system, in which system calls comprising a process generated can be viewed as antigens and the corresponding behavioral information of the system and network can be viewed as signals. The theory analysis shows that the dual detection method of DCs detecting the behavioral information caused by antigens and T cells detecting antigens can decrease false positive rate, and the model has a fast secondary response to the reinfection by the same or similar worm.
  • Keywords
    Internet; artificial immune systems; invasive software; adaptive immune system; antigens; artificial immune model; behavioral information detection; danger theory; dendritic cells; emails carrying malicious codes elimination; immunology; innate immune system; potential damage minimization; potentially threatening packets dropping; unsecure ports blocking; worm detection; worm propagation; Adaptive systems; Computer networks; Computer science; Computer worms; Distributed control; Event detection; Immune system; Intrusion detection; Signal generators; Signal processing; Dendritic cells (DCs); T cells; danger theory; negative selection; worm detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence for Modelling Control & Automation, 2008 International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    978-0-7695-3514-2
  • Type

    conf

  • DOI
    10.1109/CIMCA.2008.75
  • Filename
    5172701