期刊文献+

基于人工免疫的网络入侵动态取证 被引量:1

Dynamic Computer Forensics Based on Artificial Immune System Against Network Intrusion
下载PDF
导出
摘要 为有效提取证据,保证证据的原始性和有效性,建立了基于动态克隆选择原理的入侵监控细胞以及动态取证细胞的模型,给出了自体、非自体、抗原、检测细胞以及证据的定义。监控细胞实现对网络入侵的实时监控,并及时启动取证细胞,完成对网络入侵证据的实时提取。实验表明,该模型能有效地对多种攻击进行实时证据的提取,具有自适应性、分布性、实时性等优点,是动态计算机取证的一个较好解决方案。 In order to fetch evidences effectively and insure their originality and validity, a new method for dynamic computer forensics is presented. A model of MoC (Monitor Cell) based on dynamic clonal selection theory and a DfoC (Dynamic computer Forensics Cell) are defined. The definitions of self, non-self, detection cell and evidence are given out. The MoC surveils network intrusions real timely and start DFoC immediately when it finds intrusions. Thus the DFoC can collect evidences dynamicaly. The experiment shows that the model can effectively fetch real-time evidence of diverse attacks, and has the features of self-adaption, distribution, and real time. Therefore it is a good way for dynamic computer forensics.
出处 《四川大学学报(工程科学版)》 EI CAS CSCD 2004年第5期108-111,共4页 Journal of Sichuan University (Engineering Science Edition)
基金 国家自然科学基金资助项目(60373110) 教育部博士点基金资助项目 (2 0 0 3 0 6 1 0 0 0 3 )
关键词 人工免疫 网络入侵 计算机取证 Computer networks Immunology Real time systems Security of data
  • 相关文献

参考文献6

  • 1Reis M A,Geus P L.Standardization of computer forensic protocols and procedures[A].Proc. of 14th FIRST Conference on Computer Security Incident Handling & Response[C].Hawaii,USA,2002. 被引量:2
  • 2Kim J,Bentley P J.Towards an artificial immune system for network intrusion detection:an investigation of dynamic clonal selection[A].the Congress on Evolutionary Computation (CEC-2002)[C].Honolulu,2002.1015~1020. 被引量:1
  • 3Kim J,Bentley P J.Immune memory in the dynamic clonal selection algorithm[A].Proceedings of the First International Conference on Artificial Immune Systems (ICARIS) Canterbury[C]. 2002.57-65. 被引量:2
  • 4Kim J,Bentley P J.A model of gene library evolution in the dynamic clonal Selection Algorithm[A].Proceedings of the First International Conference on Artificial Immune Systems (ICARIS) Canterbury[C].2002.57-65. 被引量:1
  • 5KruseIIWG HeiserJG 段海新 刘武 赵乐南 译.计算机取证:应急响应精要[M].北京:人民邮电出版社,2003.. 被引量:2
  • 6SchultzEE ShumwayR 段海新 译.网络安全事件响应[M].北京:人民邮电出版社,2002.. 被引量:1

共引文献2

同被引文献11

引证文献1

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部