受生物免疫系统中主要组织相容性复合体MHC(major histocompatibility complex)分子特性的启发,提出了一种基于MHC的恶意代码检测方法MCDMHC。对抗体(检测器)恒定区和可变区分别进行编码,恒定区由MHC代码组成且保持相对稳定,这有利于保存优秀抗体基因;可变区的代码在疫苗的作用下有导向的变异,来快速获得多样性抗体以检测未知恶意代码。且建立了自体与非自体、抗原提呈以及抗体生成的动态演化方程。通过恶意代码检测对比实验表明,该方法对于恶意代码的检测率优于典型的基于免疫的AI-SCSA方法。
By drawing inspiration from the features oi major histocompatibility conpncx (MHC) in biological immune system,an MHC-inspired approach of malicious code detection was proposed. The antibody (detector) consisted of the constant region and the variable region. The constant region filled with MHC strings was to preserve outstanding antibody genes. The variable region composed of other antibodies genes fragments, was to improve the antibody diversity by mutation. The dynamic evolution of self and nonself, the presentation of antigen and the generation of antibody were discussed. Experiments were conducted on 100 malicious codes from the wildlist. Results indicate that this approach performs a relatively higher detection rate of the unknown malicious codes than that of AISCSA, a typical immune-based approach.