计算机科学 ›› 2009, Vol. 36 ›› Issue (12): 119-123.

• 软件工程与数据库技术 • 上一篇    下一篇

结合先天和适应性免疫的蠕虫检测免疫模型

张俊敏,梁意文   

  1. (武汉大学计算机学院 武汉430079)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Worm Detection Immune Model Integrating Innate and Adaptive Immunity

ZHANG Jun-min,LIANG Yi-wen   

  • Online:2018-11-16 Published:2018-11-16

摘要: 现有的蠕虫检测方法大多通过关闭不安全的端口,切断感染主机与未感染主机之间通信等方法延缓蠕虫传播而达到将损害减少到最低程度的目的。实际上在实施这些方法时往往有许多障碍需要克服,其中的最大障碍就是存在错误检测率高的问题。现将免疫危险理论中的DCs(树突状细胞,Dendritic Cells)-T细胞协同机制用于蠕虫检测,其中DCs属于先天免疫系统细胞,T细胞属于适应性免疫系统细胞。本模型将蠕虫进程触发的系统调用序列当作杭原,将感染蠕虫导致的主机和网络异常当作危险信号。在该模型中,DCs负责危险信号的收集检测并提呈与该危险信号关联的抗原给T细胞检测器进行杭原结构检测。理论分析说明,这样的双重检测方法可以降低伪肯定率和伪否定率,并且记忆T细胞检测器的采用能使系统对类似蠕虫的再次感染反应更加迅速。

关键词: 危险理论,反向选择,免疫记忆,树突状细胞,T细胞,蠕虫检测

Abstract: As most of existing worm detection methods have a number of significant hurdles to overcome in order to employ such actions as blocking unsecure ports, breaking communication between infected and non-infected hosts to slow down worm propagation and minimize potential damage. The most noteworthy obstacle is the high false positive rate problem. A recently developed hypothesis in immunology, the Danger Theory, states that our immune system responds to the presence of intruders through sensing molecules belonging to those invaders, plus signals generated by the host indicating danger and damage. Inspired by the theory,the paper proposed an artificial immune model for worm detection. The model considers the cooperation of Dendritic Cells (DCs) in the innate immune system and T cells in the adaptive immune system, in which system calls comprising a process generated can be viewed as antigens and the corresponding behavioral information of the system and network can be viewed as signals. The theory analysis shows that the dual detection method of DCs detecting the behavioral information caused by antigens and T cells detecting antigens can decrease false positive rate, and the model also has a fast secondary response to the rcinfection by the same or similar worm.

Key words: Danger theory, Negative selection, Immune memory, Dendritic cells (DCs) , T cells, Worm detection

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!