Detecting Anomalous Process Behaviour using Second Generation Artificial Immune Systems

06/18/2010
by   Jamie Twycross, et al.
0

Artificial Immune Systems have been successfully applied to a number of problem domains including fault tolerance and data mining, but have been shown to scale poorly when applied to computer intrusion detec- tion despite the fact that the biological immune system is a very effective anomaly detector. This may be because AIS algorithms have previously been based on the adaptive immune system and biologically-naive mod- els. This paper focuses on describing and testing a more complex and biologically-authentic AIS model, inspired by the interactions between the innate and adaptive immune systems. Its performance on a realistic process anomaly detection problem is shown to be better than standard AIS methods (negative-selection), policy-based anomaly detection methods (systrace), and an alternative innate AIS approach (the DCA). In addition, it is shown that runtime information can be used in combination with system call information to enhance detection capability.

READ FULL TEXT
research
10/16/2009

An Immune Inspired Approach to Anomaly Detection

The immune system provides a rich metaphor for computer security: anomal...
research
10/15/2009

An Agent Based Classification Model

The major function of this model is to access the UCI Wisconsin Breast C...
research
06/25/2010

Artificial Immune Systems (2010)

The human immune system has numerous properties that make it ripe for ex...
research
07/12/2017

Model Selection for Anomaly Detection

Anomaly detection based on one-class classification algorithms is broadl...
research
06/08/2010

ToLeRating UR-STD

A new emerging paradigm of Uncertain Risk of Suspicion, Threat and Dange...
research
08/13/2020

Statistical Evaluation of Anomaly Detectors for Sequences

Although precision and recall are standard performance measures for anom...
research
08/07/2023

Implementing Immune Repertoire Models Using Weighted Finite State Machines

The adaptive immune system's T and B cells can be viewed as large popula...

Please sign up or login with your details

Forgot password? Click here to reset