论文部分内容阅读
误警率高是当前许多入侵检测系统难以解决的难题,文章通过模拟引入生物免疫系统,抗体对入侵抗原的动态克隆扩增过程,将传统的入侵检测规则映射为生物抗体,网络数据包中包含的网络传输模式映射为生物抗原,通过抗体对抗原的识别与克隆扩增原理,判断网络入侵风险情况,以降低误报率。
The high false positive rate is a difficult problem that many intrusion detection systems can not solve at present. The article introduces the biological immune system and the dynamic amplification of invading antigen through the simulation, and maps the traditional intrusion detection rules to biological antibodies. The network packet contains The network transmission mode is mapped to bio-antigen, and the principle of antibody antigens recognition and clonal amplification is used to determine the risk of network intrusion so as to reduce the false alarm rate.