Danger theory: the link between AIS and IDS?
Aickelin, Uwe; Bentley, Peter; Cayzer, Steve; Kim, Jungwon; McLeod, Julie
We present ideas about creating a next generation Intrusion Detection System (IDS) based on the latest immunological theories. The central challenge with computer security is determining the difference between normal and potentially
harmful activity. For half a century, developers have protected their systems by coding rules that identify and block specific events. However, the nature of current
and future threats in conjunction with ever larger IT systems urgently requires the development of automated and adaptive defensive tools. A promising solution is emerging in the form of Artificial Immune Systems (AIS): The Human Immune System (HIS) can detect and defend against harmful and previously unseen invaders, so can we not build a similar Intrusion Detection System (IDS) for our computers?
Presumably, those systems would then have the same beneficial properties as HIS like error tolerance, adaptation and self-monitoring. Current AIS have been successful on test systems, but the algorithms rely on self-nonself discrimination, as stipulated in classical immunology. However, immunologist are increasingly finding fault with traditional self-nonself thinking and a new ‘Danger Theory’ (DT) is emerging. This new theory suggests that the immune system reacts to threats based on the correlation of various (danger) signals and it provides a method of ‘grounding’ the immune response, i.e. linking it directly to the attacker. Little is currently understood of the precise nature and correlation of these signals and the theory is a topic of hot debate. It is the aim of this research to investigate this correlation and to translate the DT into the realms of computer security, thereby creating AIS that are no longer limited by self-nonself discrimination. It should be noted that we do not intend to defend this controversial theory per se, although as a deliverable this project will add to the body of knowledge in this area. Rather we are interested in its merits for scaling up AIS applications by overcoming self-nonself discrimination problems.
Aickelin, U., Bentley, P., Cayzer, S., Kim, J., & McLeod, J. (2003). Danger theory: the link between AIS and IDS?. In P. Bentley, J. Timmis, & E. Hart (Eds.), Artificial immune systems: second international conference, ICARIS 2003, Edinburgh, UK, September 1-3, 2003: proceedingsSpringer. doi:10.1007/978-3-540-45192-1_15
|Publication Date||Jan 1, 2003|
|Deposit Date||Feb 18, 2009|
|Publicly Available Date||Feb 18, 2009|
|Journal||Proceedings of the 2nd International Conference on Artificial Immune Systems (ICARIS2003), Edinburgh, UK|
|Peer Reviewed||Peer Reviewed|
|Book Title||Artificial immune systems: second international conference, ICARIS 2003, Edinburgh, UK, September 1-3, 2003: proceedings|
|Additional Information||The original publication is available at www.springerlink.com|
You might also like
Measuring behavioural change of players in public goods game
Adaptive Data Communication Interface: A User-Centric Visual Data Interpretation Framework
Identifying candidate risk factors for prescription drug side effects using causal contrast set mining
Indebted households profiling: a knowledge discovery from database approach