论文部分内容阅读
当入侵者侵入服务器或者终端的操作系统,此时主机的操作系统将不再受信任.网络存储系统应当识别出这种入侵.基于存储的入侵检测系统SIDS(Storage-based intrusion detection systems)能在存储层观察到此类入侵行为.本文提出一种新的基于存储的人工免疫入侵检测方案.该方案克服了以往一些SIDS原型完全依赖规则的缺点,利用了人工免疫的自我免疫特性,来动态监控用户的访问行为.根据收敛速度和检测效率,拟合出本方案的最优参数.最后的仿真结果表明:与同类优秀原型相比,本方案能达到较高的检测率和较低的误警率.
When an intruder invades the operating system of the server or the terminal, the operating system of the host is no longer trusted, and the network storage system should recognize such an intrusion. The storage-based intrusion detection systems (SIDS) This kind of intrusion behavior is observed in the storage layer.This paper presents a new memory-based artificial immune intrusion detection scheme.This scheme overcomes the shortcomings that some SIDS prototypes are completely dependent on the rules in the past and makes use of the autoimmune characteristics of artificial immunity to dynamically monitor The user’s access behavior.According to the convergence speed and detection efficiency, the optimal parameters of this scheme are fitted.Finally, the simulation results show that this scheme can achieve higher detection rate and lower false alarm rate.