针对目前基于免疫的入侵检测模型自适应性较差,缺少定量描述及成熟检测器生成效率不高等问题,提出了一种新型的入侵防御模型.建立了抗原、抗体的形式化描述及动力学方程;提出了一种由随机产生和基因库相结合的未成熟抗体生成机制和基于基因驱动的检测器进化算法,并采用疫苗注射方法提高网络的整体防御能力;通过收集到的真实网络数据及KDDCup1999评估数据对模型进行了仿真对比实验.结果表明,本模型具有更好的检测性能,有效提高了网络的安全防御能力.
An immune-based novel model for intrusion prevention was proposed to solve the problems of available intrusion detections models. The formal description and dynamic equations of Ag and Ab were designed, and a gene-driver method to generate detectors was also proposed. At the same time, a vaccine-injection method was introduced to improve the whole preventions of the network. At last, the simulation experiments were done to test the model. The experimental data included the data collected from the actual lan and KDDCup1999 evaluation data sets. The experimental results prove the model has better detection performance. If the model will be varied properly, it also can be used in the fields of virus detection and spam mail recognition.