|
|
||||||||
|
|||||||||
|
Technical Report: DCC-2006-04Towards a new Immunity-Inspired Intrusion Detection FrameworkMário J. AntunesDepartamento de Ciência de ComputadoresFaculdade de Ciências da Universidade do Porto E-mail: mario.antunes@estg.ipleiria.pt andManuel E. CorreiaDepartamento de Ciência de Computadores Faculdade de Ciências da Universidade do Porto E-mail: mcc@dcc.fc.up.pt AbstractIn this document we introduce a novel framework for behaviour based Network Intrusion Detection Systems (NIDS). Its main goal is the application of theoretical immunological concepts to provide adaptability to the normality of the network behaviour, based on memory and learning from previous attacks. We present some important principles and concepts relevant to the description and categorization of Intrusion Detection Systems (IDS), and then describe the main benefits that can be obtained from an Artificial Immune System (AIS) approach for IDS. We conclude by proposing a novel extension to the Common Intrusion Detection Framework (CIDF) capable of accommodating our initial goals. |
||||||||
|