Design and implementation of real-time network risk control system based on antibody concentration

GAO Zhiqiang,HU Xiaoqin
DOI: https://doi.org/10.11772/j.issn.1001-9081.2013.10.2842
2013-01-01
Journal of Computer Applications
Abstract:The system adopted artificial immune theory.Through analyzing the detection results of the traditional realtime intrusion detection system Snort,and according to the characteristic that antibody concentration dynamically changes with the network intrusion intensity,the current risk value of network was calculated to reflect all kinds of attacks and overall risk profile.Snort relies on the rule matching to detect data packets.The detection process does not take into account the current network risk,resulting in the problem of high false positives rate.This system set pass threshold and dropped threshold based on different degree of attack danger to reduce the false alarm rate of Snort,and took pass,alarm,discard packet,etc. as response measures according to the risk value.The experimental results show that the system can calculate the real-time risk faced by the host and network accurately,reduce the false positive rate and take response measures according to risk value effectively.
What problem does this paper attempt to address?