Dissertation > Excellent graduate degree dissertation topics show

The Study of Unknown Internet Worm IDS Based on Artificial Immune System

Author: ChenBaoJun
Tutor: LiDaXing
School: Shandong University
Course: System Analysis and Integration
Keywords: Artificial Immune Danger Theory DCA Intrusion Detection Network worms
CLC: TP393.08
Type: Master's thesis
Year: 2008
Downloads: 127
Quote: 1
Read: Download Dissertation

Abstract


Modern society, the increasing reliance on the Internet, and the types of malicious code threat to computer security is gradually increasing. Network worms exploit system vulnerabilities to spread malicious code, which has to take the initiative to spread, without the host, variants and fast deformation characteristics, its harmfulness is bigger and wider than ordinary virus. Timely and accurate detection of network worms, the protection of computer systems and networks from malicious code threats academia has been discussed important topics for the the worm antivirus system has been built, but most anti-virus and intrusion detection systems are already worms established feature database testing, and the high rate of false positives for new or deformation of worms, response lag, still cause damage to computer systems and networks. Zero time response to make the unknown network worm detection system to make the adjustment to adapt to and distributed environment, the changes in the network environment, has an important significance of computer security, where the purpose of this study. Intrusion detection system in detection technology, including feature-based detection and anomaly-based detection: feature-based detection technology intrusion feature extraction, to create a feature library, pattern matching can make timely and accurate is invasion Analyzing However, to implement new network worm detection the powerless; based on the abnormality detection technique is to define the normal values ??of the system, contrary to normal as an intrusion, but this technique is, in a normal case, it is easy error intrusion Analyzing. , Purdue University, the University of California, Davis, Columbia University, New Mexico University and other institutions in the intrusion detection system is intelligent and distributed in both directions in the system to achieve the anticipated results. Intrusion detection system is lagging behind, in the initial stage of Intrusion Detection Technology. Based intrusion detection mechanism of biological immune system is even more striking, to promote the study of the current network security is of great significance, especially for intrusion detection technology provides an important basis. The primary means of living organisms against external invasion and safeguard their own security and stability is to rely on their own defense system and immunity against external computer system defense worms and biological invasion has striking similarities. In this paper, based on artificial immune system of the unknown network worm intrusion detection systems, the use of new immune theory - Danger Theory and the DCA immune algorithm, designed to detect unknown network worm detection system model, the various functional modules in the system detailed design description and implementation. This paper first introduces the definition and features of the network worm, after the introduction of the characteristics and mechanism of the biological immune system, and an overview of current research status based on artificial immune intrusion detection, elaborated Danger Theory and Julie Greensmith researchers DCA algorithm. The scan function worms wanton spread, the detected scanning invasion undoubtedly up to find the purpose of defense unknown network worm. Based on this, the last part of this paper, designed to detect port scanning system model, the various features modular design and simple implementation using an object-oriented language C. The model consists of data collection, data pre-processing, data processing and data analysis modules. Characterized spent in the data pre-processing, data processing and data analysis module improved DCA algorithm, scan abstract the eight signal supplied to the DCA algorithm processing. The detection model having a false positive rate and false negative rate, and can detect unknown worms, having a good robustness, combined with the existing intrusion detection technology can play a better role. In Shandong Province, China Netcom centralized network management project internship, participated in the design and development of system security management functions and system operation security environment configuration, on completion of this article.

Related Dissertations

  1. Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
  2. Improving of Artificial Imune Classification and Anomaly Detection Algorithms,R392.1
  3. Study on Quantitative Ecology of Gleditsia Heterophylla Communities in the Southern Tip of Taihang Mountains, Shanxi,Q948
  4. Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
  5. Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
  6. The Research on Intrusion Detection System Based on Machine Learning,TP393.08
  7. Our college crisis management early warning system,G647.1
  8. Intrusion Detection in Mobile Ad Hoc Networks: A Timed Finite State Machines Approach,TN929.5
  9. Virus Detection Technology Based on Artificial Immune,TP393.08
  10. An Intrusion Detection System for High-Speed Networks,TP393.08
  11. Research on the Security in Wireless Sensor Network,TN915.08
  12. Sensitivity Analysis and Application of Orthogonal Weight Function Neural Network,TP183
  13. The Study of Intelligent Intrusion Detection System Based on Neural Network in Linux,TP393.08
  14. Petri net -based network intrusion detection system Research and Implementation,TP393.08
  15. FSVM -based data mining method and its application to intrusion detection research,TP393.08
  16. Web-based intrusion detection system logs Design and Implementation,TP393.08
  17. IPv4-IPv6 transition technologies CIDF Based Intrusion Detection System,TP393.08
  18. Intrusion detection based on data mining technology research,TP393.08
  19. Based on Petri net modeling intelligent algorithm for job shop scheduling,TP18
  20. Mechanisms based on trust metrics Research and Implementation of Intrusion Detection System,TP393.08
  21. Helicopter transmission chain fault diagnosis and health management system design and key technology research,V267

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile