2010/06/18 by Jamie Twycross, Twycross, Jamie, Uwe Aickelin +3
Engineering · #Artificial Immune Systems Applications #Artificial Intelligence (cs.AI) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Neural and Evolutionary Computing (cs.NE)
paper · pdf · doi:10.48550/arxiv.1006.3654
openalex publication_date 2010/06/18 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Artificial Immune Systems have been successfully applied to a number of\nproblem domains including fault tolerance and data mining, but have been shown\nto scale poorly when applied to computer intrusion detec- tion despite the fact\nthat the biological immune system is a very effective anomaly detector. This\nmay be because AIS algorithms have previously been based on the adaptive immune\nsystem and biologically-naive mod- els. This paper focuses on describing and\ntesting a more complex and biologically-authentic AIS model, inspired by the\ninteractions between the innate and adaptive immune systems. Its performance on\na realistic process anomaly detection problem is shown to be better than\nstandard AIS methods (negative-selection), policy-based anomaly detection\nmethods (systrace), and an alternative innate AIS approach (the DCA). In\naddition, it is shown that runtime information can be used in combination with\nsystem call information to enhance detection capability.\n