Synthesizing of intrusion prevention system based on the association of human immune system and operating system
Matematičeskoe modelirovanie, Tome 19 (2007) no. 12, pp. 3-12

Voir la notice de l'article provenant de la source Math-Net.Ru

Current approaches to intrusion detection are generally based on the observation of only one source of information such as network traffic, resource usage, logs etc. In this paper we would get a more precise conclusion about the incident of intrusion if we used all the available information. In this paper we are going to present an approach to an Intrusion Prevention System (IPS) which tries to solve this problem and trigger an active response exclusively for dangerous security events. We will show how to link The Danger Theory of immunology with components of the operating system for the synthesizing of intrusion prevention system. We'll also propose a technique inspired by the clonal selection mechanism of the immune system which links the anomaly behavior of system processes with received network traffic and can generate new signatures of network intrusions on the fly. We'll discuss an implementation of this approach based on the example of a developed prototype which works in the kernel space of Linux. Our IPS combines signature and anomaly based approaches and balances between corresponding modules using several methods.
@article{MM_2007_19_12_a0,
     author = {A. V. Krizhanovsky and A. M. Marasanov},
     title = {Synthesizing of intrusion prevention system based on the association of human immune system and operating system},
     journal = {Matemati\v{c}eskoe modelirovanie},
     pages = {3--12},
     publisher = {mathdoc},
     volume = {19},
     number = {12},
     year = {2007},
     language = {ru},
     url = {http://geodesic.mathdoc.fr/item/MM_2007_19_12_a0/}
}
TY  - JOUR
AU  - A. V. Krizhanovsky
AU  - A. M. Marasanov
TI  - Synthesizing of intrusion prevention system based on the association of human immune system and operating system
JO  - Matematičeskoe modelirovanie
PY  - 2007
SP  - 3
EP  - 12
VL  - 19
IS  - 12
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/MM_2007_19_12_a0/
LA  - ru
ID  - MM_2007_19_12_a0
ER  - 
%0 Journal Article
%A A. V. Krizhanovsky
%A A. M. Marasanov
%T Synthesizing of intrusion prevention system based on the association of human immune system and operating system
%J Matematičeskoe modelirovanie
%D 2007
%P 3-12
%V 19
%N 12
%I mathdoc
%U http://geodesic.mathdoc.fr/item/MM_2007_19_12_a0/
%G ru
%F MM_2007_19_12_a0
A. V. Krizhanovsky; A. M. Marasanov. Synthesizing of intrusion prevention system based on the association of human immune system and operating system. Matematičeskoe modelirovanie, Tome 19 (2007) no. 12, pp. 3-12. http://geodesic.mathdoc.fr/item/MM_2007_19_12_a0/