Immunity-based intrusion detection system design, vulnerability analysis, and GENERTIA's genetic arms race

Author(s):  
Haiyu Hou ◽  
Gerry Dozier
2013 ◽  
Vol 347-350 ◽  
pp. 2860-2864 ◽  
Author(s):  
Jia Wei Du ◽  
Xing Zhang ◽  
Ying Zhou ◽  
Yong Qiang Bai

As the traditional network defense is built on intrusion detection and passive protection, which is weak at dynamic response. The network deception technology in active protection is analyzed, and a network deception system based on active security model is proposed in this paper. This system implements a visual service of Honeypot as bait, analyses intrusion data and extracts new features and rules to enlarge the intrusion detection system feature library. The defense policies could be delivered real-time by management center. The problems of false alarm and leaking alarm for firewall or IDS are improved. And the limitations of single technology on the cooperation are overcome by linkage of Honeypot, firewall, IDS and router. The efficiency of unknown intrusion detected is increased.


Sign in / Sign up

Export Citation Format

Share Document