Research on Intrusion Detection Technology Based on Theory of Immunity

李建飞,吴国新
DOI: https://doi.org/10.3969/j.issn.1673-629x.2005.01.042
2005-01-01
Abstract:A kind of delamination-detection and distributed IDS model based on complete analyzing the immunity theory is put forward.The model has the characters of real-time,self-adaptability,expansibility,intelligence because the model can realize immunity by creating the auto-matching detection rule collection by adopting four layers divided from the detection rule database.After these detection rule collections are reverse-filtered they are separately injected the mobile detection agent(MDA) which has corresponding detection rule collection.Then these MDAs corporately execute intrusion detection and response.Having the immunity,the multi-agents can carry out delamination-detecting and response to the great-flux and distributed network,and can dectect the intrusion and attack in local and whole network.
What problem does this paper attempt to address?