This paper analyzes the feasibility of applying artificial immune theory in network-based intrusion detection,establishes a model combining artificial immune theory and data mining technique and describes the algorithms used in the process of anti-body's production.
在分析入侵检测系统通用模型和传统模型的基础上,研究和分析了近年来具有代表性的几种新的入侵检测系统模型,并展望了未来入侵检测系统模型的发展方向.
Objective: Present a new features selection algorithm. Methods: based on rule induction and field knowledge. Results: This algorithm can be applied in catching dataflow when detecting network intrusions, only the sub-dataset including discriminating features is catched. Then the time spend in following behavior patterns mining is reduced and the patterns mined are more precise. Conclusion: The experiment results show that the feature subset catched by this algorithm is more informative and the dataset's quantity is reduced significantly.