{"title":"The Method of Classified Danger Sensed for Windows Process Intrusion Detection","authors":"Fei Xu, Chengyu Tan, Yi Zheng, M. Geng","doi":"10.1109/ICMECG.2009.72","DOIUrl":null,"url":null,"abstract":"Once the computer system is intruded, the change from normal to abnormal is a gradual procedure. Setting up a calculating model based on Danger Theory for danger signal during the procedure will improve the accuracy and efficiency of Artificial Immune System (AIS) greatly. In this paper, the method of classified danger sensed (MCDS) for Windows process intrusion detection based on Danger Theory is proposed. This method divides the process’s behavior parameters into two types: numeric and non-numeric types, using the function’s difference and correlation coefficient to analyze the rule and relevance of numeric parameters’ change, and evaluating the degree of danger of non-numeric parameters by analyzing the danger level and Time Relationship(TR) of data. Based on these methods, we establish calculating models of numeric and non-numeric danger signals separately, finally give the definition and calculating method of \" Danger Degree \".","PeriodicalId":252323,"journal":{"name":"2009 International Conference on Management of e-Commerce and e-Government","volume":"99 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-09-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 International Conference on Management of e-Commerce and e-Government","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICMECG.2009.72","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Once the computer system is intruded, the change from normal to abnormal is a gradual procedure. Setting up a calculating model based on Danger Theory for danger signal during the procedure will improve the accuracy and efficiency of Artificial Immune System (AIS) greatly. In this paper, the method of classified danger sensed (MCDS) for Windows process intrusion detection based on Danger Theory is proposed. This method divides the process’s behavior parameters into two types: numeric and non-numeric types, using the function’s difference and correlation coefficient to analyze the rule and relevance of numeric parameters’ change, and evaluating the degree of danger of non-numeric parameters by analyzing the danger level and Time Relationship(TR) of data. Based on these methods, we establish calculating models of numeric and non-numeric danger signals separately, finally give the definition and calculating method of " Danger Degree ".