Result: Anomaly detection in TCP/IP networks using immune systems paradigm

Title:
Anomaly detection in TCP/IP networks using immune systems paradigm
Source:
Computer communications. 30(4):740-749
Publisher Information:
Amsterdam; New York, NY; Tokyo: Elsevier Science, 2007.
Publication Year:
2007
Physical Description:
print, 22 ref
Original Material:
INIST-CNRS
Document Type:
Conference Conference Paper
File Description:
text
Language:
English
Author Affiliations:
Polish-Japanese Institute of Information Technology, Koszykowa 86, 02-008 Warsaw, Poland
Institute of Computer Science, Polish Academy of Sciences, Ordona 21, 01-237 Warsaw, Poland
Faculty of Sciences, Technology and Communication, Luxembourg University, 6 rue Coudenhove Kalergi, 1359 Luxembourg-Kirchberg, Luxembourg
ISSN:
0140-3664
Rights:
Copyright 2007 INIST-CNRS
CC BY 4.0
Sauf mention contraire ci-dessus, le contenu de cette notice bibliographique peut être utilisé dans le cadre d’une licence CC BY 4.0 Inist-CNRS / Unless otherwise stated above, the content of this bibliographic record may be used under a CC BY 4.0 licence by Inist-CNRS / A menos que se haya señalado antes, el contenido de este registro bibliográfico puede ser utilizado al amparo de una licencia CC BY 4.0 Inist-CNRS
Notes:
Computer science; theoretical automation; systems
Accession Number:
edscal.18529350
Database:
PASCAL Archive

Further Information

The paper presents an architecture of an anomaly detection system based on the paradigm of artificial immune systems (AISs). Incoming network traffic data are considered by the system as signatures of potential attackers by mapping them into antigens of AISs either using some parameters of network traffic or headers of selected TCP/IP protocols. A number of methods of generation of antibodies (anomaly detectors) were implemented. The way of anomaly detection depends on the method of antibodies generation. The paper presents results of an experimental study performed with use of real data and shows how the performance of the anomaly detection system depends on traffic data coding and methods of generation of detectors.