对仿生免疫系统GECISM(General Computer Immune System Model),沙盒主机是其中的一个主要代理。文章详细介绍了沙盒主机中“非我”检测与分类的结构。通过定义安全相关调用,对采集形成的安全相关调用短序列进行训练,生成序列库和规则库...对仿生免疫系统GECISM(General Computer Immune System Model),沙盒主机是其中的一个主要代理。文章详细介绍了沙盒主机中“非我”检测与分类的结构。通过定义安全相关调用,对采集形成的安全相关调用短序列进行训练,生成序列库和规则库,从而对“非我”进行检测和分类,同时对测试程序“非我”类型的分布进行了讨论。实验证明了用此方法进行“非我”检测和分类的可行性和高效性。展开更多
A clone selection algorithm for computer immune system is presented. Clone selection principles in biological immune system are applied to the domain of computer virus detection. Based on the negative selection algori...A clone selection algorithm for computer immune system is presented. Clone selection principles in biological immune system are applied to the domain of computer virus detection. Based on the negative selection algorithm proposed by Stephanie Forrest, combining mutation operator in genetic algorithms and niching strategy in biology is adopted, the number of detectors is decreased effectively and the ability on self-nonself discrimination is improved. Simulation experiment shows that the algorithm is simple, practical and is adapted to the discrimination for long files.展开更多
为了保证计算机免疫系统GECISM(GEneral Computer Immune System Model)根据数据库的当前状态做出一致性的响应,从而提高计算机免疫系统的执行效率,给出了保证知识库一致性的方法,也就是对于进入处理器中需要进行处理的进程,在没有用户...为了保证计算机免疫系统GECISM(GEneral Computer Immune System Model)根据数据库的当前状态做出一致性的响应,从而提高计算机免疫系统的执行效率,给出了保证知识库一致性的方法,也就是对于进入处理器中需要进行处理的进程,在没有用户干预的情况下,各客户机里的规则库可以给出一致的进行"自我"和"非我"的判断,从而提高系统的处理能力。展开更多
文摘对仿生免疫系统GECISM(General Computer Immune System Model),沙盒主机是其中的一个主要代理。文章详细介绍了沙盒主机中“非我”检测与分类的结构。通过定义安全相关调用,对采集形成的安全相关调用短序列进行训练,生成序列库和规则库,从而对“非我”进行检测和分类,同时对测试程序“非我”类型的分布进行了讨论。实验证明了用此方法进行“非我”检测和分类的可行性和高效性。
文摘A clone selection algorithm for computer immune system is presented. Clone selection principles in biological immune system are applied to the domain of computer virus detection. Based on the negative selection algorithm proposed by Stephanie Forrest, combining mutation operator in genetic algorithms and niching strategy in biology is adopted, the number of detectors is decreased effectively and the ability on self-nonself discrimination is improved. Simulation experiment shows that the algorithm is simple, practical and is adapted to the discrimination for long files.
文摘为了保证计算机免疫系统GECISM(GEneral Computer Immune System Model)根据数据库的当前状态做出一致性的响应,从而提高计算机免疫系统的执行效率,给出了保证知识库一致性的方法,也就是对于进入处理器中需要进行处理的进程,在没有用户干预的情况下,各客户机里的规则库可以给出一致的进行"自我"和"非我"的判断,从而提高系统的处理能力。