提出了一种基于人工免疫的入侵检测动态响应模型,给出了关于自体、非自体、抗原、免疫细胞等的表达式,建立了基于克隆选择的入侵检测模型,在此基础上,给出了响应成本和系统损失的定量计算公式,建立了基于代价的动态响应模型。该模型具有自适应性、实时性、定量计算等优点,是网络入侵检测动态响应的一个较好解决方案。
A new immunity based dynamic intrusion detection response model is presented. An intrusion detection mechanism based on self-tolerance, clone selection, and immune surveillance was established. The method that uses antibody concentration to quantitatively describe the degree of intrusion danger was demonstrated. And quantitative calculations of response cost and benefit were achieved. The response decision-making mechanism of maximum response benefit was developed, and a dynamic intrusion response system was set up. This model is a good solution to intrusion response in the network.