针对传统木马检测技术比较被动这一缺陷,提出一种基于人工免疫原理的木马检测方法。利用人工免疫具有自适应以及免疫学习能力的特点,将人工免疫原理应用到木马检测中。分析了数据来源特征,给出了计算抗体与抗原或抗体与抗体之间相似度以及抗体的适应度公式,建立了一个木马检测系统模型;实验测试了利用人工免疫的方式检测木马能有效提高木马检测的检测率,减少误报率。
According to the defects of the traditional technology, of the detection of the Trojan, gave a method of the Trojan detection based on the artificial immune principle. Applied the artificial immune principle in the Trojan detection because of the adaptive and the immunity study capacity. Analyzed the source of the data features; gave the formula of the similarity calculation of the antibody and antigen or both of the antibodies and the fitness calculation of the antibodies. Founded the model of the Trojan detection system. Gave the test of the Trojan detection based on the artificial immune principle to prove that this Trojan detection system can improve the detection rate and reduce the rate of false alarm.