Cải Tiến Một Số Thuật Toán Trong Miễn Dịch Nhân Tạo Để Phát Hiện Xâm Nhập Mạng

Luận án tiến sĩ toán học nghiên cứu cải tiến một số thuật toán trong miễn dịch nhân tạo cho phát hiện xâm nhập mạng, phân tích chuyên sâu, xây dựng mô hình lý thuyết, đề xuất giải

Trường đại học

Vietnamese Academy of Science and Technology

Chuyên ngành

Mathematical Foundations for Informatics

Tác giả

Nguyen Van Truong

Người đăng

Ẩn danh

Thể loại

thesis

2019

103
1
0

Phí lưu trữ

35 Point

Mục lục chi tiết

Acknowledgments

Certificate of Originality

Contents

List of Figures

List of Tables

Notation and Abbreviation

1. INTRODUCTION

1.1. Motivation

1.2. Objectives

1.3. Problem statements

1.4. Outline of thesis

2. Chapter 1: BACKGROUND

2.1. Detection of Network Anomalies

2.1.1. Host-Based IDS

2.1.2. Network-Based IDS

2.2. Methods

3. 2 COMBINATION OF NEGATIVE SELECTION AND POSITIVE SELECTION

4. 3 GENERATION OF COMPACT DETECTOR SET

5. 4 FAST SELECTION ALGORITHMS

6. 5 APPLYING HYBRID ARTIFICIAL IMMUNE SYSTEM FOR NETWORK SECURITY

7. CONCLUSIONS

7.1. Contributions of this thesis

BIBLIOGRAPHY

Tóm tắt

I. Tổng quan về Cải tiến Thuật Toán Miễn Dịch Nhân Tạo cho Phát Hiện Xâm Nhập Mạng

Trong bối cảnh an ninh mạng ngày càng trở nên phức tạp, việc phát triển các hệ thống phát hiện xâm nhập (IDS) hiệu quả là rất cần thiết. Thuật toán miễn dịch nhân tạo (AIS) đã nổi lên như một giải pháp tiềm năng nhờ khả năng học hỏi và thích ứng với các mối đe dọa mới. Nghiên cứu này tập trung vào việc cải tiến các thuật toán AIS nhằm nâng cao hiệu suất phát hiện xâm nhập mạng.

1.1. Ứng dụng của AIS trong An ninh Mạng

AIS được thiết kế dựa trên nguyên lý hoạt động của hệ miễn dịch con người, giúp phát hiện và phân loại các hành vi xâm nhập. Các nghiên cứu đã chỉ ra rằng AIS có thể cải thiện khả năng phát hiện các mối đe dọa chưa biết.

1.2. Tầm quan trọng của Phát hiện Xâm nhập Mạng

Phát hiện xâm nhập mạng là một phần quan trọng trong chiến lược bảo mật tổng thể. Hệ thống IDS giúp bảo vệ dữ liệu và tài nguyên mạng khỏi các cuộc tấn công, đồng thời cung cấp thông tin phản hồi kịp thời cho các chuyên gia an ninh.

II. Thách thức trong Phát hiện Xâm nhập Mạng hiện nay

Mặc dù có nhiều tiến bộ trong công nghệ phát hiện xâm nhập, nhưng vẫn tồn tại nhiều thách thức lớn. Các vấn đề như tỷ lệ báo động giả cao, thời gian huấn luyện dài và sự thay đổi liên tục của các định nghĩa về dữ liệu bình thường và bất thường vẫn là những trở ngại lớn.

2.1. Tỷ lệ báo động giả và báo động thiếu

Tỷ lệ báo động giả cao có thể dẫn đến sự mất niềm tin vào hệ thống IDS. Điều này đòi hỏi các thuật toán phải được cải tiến để giảm thiểu các báo động không chính xác.

2.2. Thời gian huấn luyện và kiểm tra dài

Thời gian huấn luyện dài có thể làm giảm khả năng phản ứng nhanh của hệ thống trước các cuộc tấn công. Cần có các phương pháp tối ưu hóa để rút ngắn thời gian này.

III. Phương pháp Cải tiến Thuật Toán Miễn Dịch Nhân Tạo

Nghiên cứu này đề xuất một số phương pháp cải tiến cho thuật toán miễn dịch nhân tạo nhằm nâng cao hiệu suất phát hiện xâm nhập. Các phương pháp này bao gồm việc kết hợp các thuật toán chọn lọc và tối ưu hóa cấu trúc dữ liệu.

3.1. Kết hợp Thuật toán Chọn lọc Âm và Dương

Phương pháp này giúp tối ưu hóa việc phát hiện bằng cách sử dụng cả hai loại thuật toán chọn lọc âm và dương, từ đó cải thiện độ chính xác của hệ thống.

3.2. Tối ưu hóa Cấu trúc Dữ liệu

Việc sử dụng cấu trúc dữ liệu hiệu quả có thể giảm thiểu thời gian xử lý và tăng tốc độ phát hiện xâm nhập, từ đó nâng cao hiệu suất tổng thể của hệ thống.

IV. Ứng dụng Thực tiễn của AIS trong An ninh Mạng

Các ứng dụng thực tiễn của AIS trong an ninh mạng đã cho thấy hiệu quả rõ rệt trong việc phát hiện các mối đe dọa. Nghiên cứu đã chỉ ra rằng AIS có thể được áp dụng trong nhiều lĩnh vực khác nhau, từ bảo mật mạng doanh nghiệp đến bảo vệ thông tin cá nhân.

4.1. AIS trong Bảo mật Doanh nghiệp

Nhiều doanh nghiệp đã áp dụng AIS để bảo vệ hệ thống của họ khỏi các cuộc tấn công mạng, giúp giảm thiểu thiệt hại và tăng cường an ninh thông tin.

4.2. AIS trong Bảo vệ Thông tin Cá nhân

AIS cũng được sử dụng để bảo vệ thông tin cá nhân của người dùng, giúp phát hiện và ngăn chặn các hành vi xâm phạm quyền riêng tư.

V. Kết luận và Tương lai của Cải tiến AIS

Nghiên cứu này đã chỉ ra rằng việc cải tiến thuật toán miễn dịch nhân tạo có thể mang lại nhiều lợi ích cho hệ thống phát hiện xâm nhập mạng. Tương lai của AIS trong an ninh mạng hứa hẹn sẽ tiếp tục phát triển với nhiều ứng dụng mới và cải tiến kỹ thuật.

5.1. Hướng đi Tương lai cho Nghiên cứu AIS

Cần tiếp tục nghiên cứu và phát triển các thuật toán AIS mới để đáp ứng các thách thức trong an ninh mạng ngày càng phức tạp.

5.2. Tích hợp AIS với Công nghệ Mới

Việc tích hợp AIS với các công nghệ mới như học máy và trí tuệ nhân tạo có thể mở ra nhiều cơ hội mới trong việc phát hiện và ngăn chặn các mối đe dọa mạng.

Tóm tắt và mô tả trên trang này được tạo với sự hỗ trợ của AI. Nếu bạn thấy nội dung không chính xác hoặc có vấn đề, vui lòng Báo lỗi nội dung.

27/07/2025
Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch nhân tạo cho phát hiện xâm nhập mạng

Trích đoạn nội dung tài liệu

MINISTRY OF EDUCATION VIETNAMESE ACADEMY AND TRAINING OF SCIENCE AND TECHNOLOGY GRADUATE UNIVERSITY OF SCIENCE AND TECHNOLOGY ———————————— NGUYEN VAN TRUONG IMPROVING SOME ARTIFICIAL IMMUNE ALGORITHMS FOR NETWORK INTRUSION DETECTION THE THESIS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY IN MATHEMATICS Hanoi - 2019 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com MINISTRY OF EDUCATION VIETNAMESE ACADEMY AND TRAINING OF SCIENCE AND TECHNOLOGY GRADUATE UNIVERSITY OF SCIENCE AND TECHNOLOGY ———————————— NGUYEN VAN TRUONG IMPROVING SOME ARTIFICIAL IMMUNE ALGORITHMS FOR NETWORK INTRUSION DETECTION THE THESIS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY IN MATHEMATICS Major: Mathematical foundations for Informatics Code: 62 46 01 10 Scientific supervisor: 1. Nguyen Xuan Hoai 2. Luong Chi Mai Hanoi - 2019 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com Acknowledgments First of all I would like to thank is my principal supervisor, Assoc. Nguyen Xuan Hoai for introducing me to the field of Artificial Immune System.

He guides me step by step through research activities such as seminar presentations, paper writing, etc. His genius has been a constant source of help. I am intrigued by his constructive criticism throughout my PhD. I wish also to thank my co-supervisor, Assoc.

Luong Chi Mai. She is always very enthusiastic in our discussion promising research questions. It is a pleasure and luxury for me to work with her. This thesis could not have been possible without my supervisors’ support.

I gratefully acknowledge the support from Institute of Information Technology, Vietnamese Academy of Science and Technology, and from Thai Nguyen University of Education. I thank the financial support from the National Foundation for Science and Technology Development (NAFOSTED), ASEAN-European Academic University Network (ASEA-UNINET). Vu Duc Quang, M. Trinh Van Ha and M.

Pham Dinh Lam, my co-authors of published papers. Tran Quang Anh and Dr. Nguyen Quang Uy for many helpful insights for my research. I thank colleagues, especially my cool labmate Mr.

Nguyen Tran Dinh Long, in IT Research & Development Center, HaNoi University. Finally, I thank my family for their endless love and steady support. LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com Certificate of Originality I hereby declare that this submission is my own work under my scientific super- visors, Assoc. Nguyen Xuan Hoai, and Assoc.

Luong Chi Mai. I declare that, it contains no material previously published or written by another person, except where due reference is made in the text of the thesis. In addition, I certify that all my co-authors allow me to present our work in this thesis. student Nguyen Van Truong LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com i Contents List of Figures v List of Tables vii Notation and Abbreviation viii INTRODUCTION 1 Motivation.

2 Outline of thesis .1 Detection of Network Anomalies .1 Host-Based IDS .2 Network-Based IDS .2 A brief overview of human immune system .3 AIS for IDS .1 AIS model for IDS .2 AIS features for IDS .1 Negative Selection Algorithms. 12 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.2 Positive Selection Algorithms .5 Basic terms and definitions .1 Strings, substrings and languages .2 Prefix trees, prefix DAGs and automata .4 Detection in r-chunk detector-based positive selection .7 Ring representation of data .1 The DARPA-Lincoln datasets. 29 2 COMBINATION OF NEGATIVE SELECTION AND POSITIVE SE- LECTION 30 2.3 New Positive-Negative Selection Algorithm. 40 3 GENERATION OF COMPACT DETECTOR SET 43 3.3 New negative selection algorithm.

45 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.1 Detectors set generation under rcbvl matching rule .2 Detection under rcbvl matching rule. 49 4 FAST SELECTION ALGORITHMS 51 4.3 A fast negative selection algorithm based on r-chunk detector .4 A fast negative selection algorithm based on r-contiguous detector. 65 5 APPLYING HYBRID ARTIFICIAL IMMUNE SYSTEM FOR NET- WORK SECURITY 66 5.3 Hybrid positive selection algorithm with chunk detectors .3 Performance metrics and parameters. 76 CONCLUSIONS 78 Contributions of this thesis.

80 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com iv BIBLIOGRAPHY 81 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com v List of Figures 1.1 Classification of anomaly-based intrusion detection methods .2 Multi-layered protection and elimination architecture .3 Multi-layer AIS model for IDS .4 Outline of a typical negative selection algorithm.5 Outline of a typical positive selection algorithm.6 Example of a prefix tree and a prefix DAG.7 Existence of holes.8 Negative selections with 3-chunk and 3-contiguous detectors.9 A simple ring-based representation (b) of a string (a).10 Frequency trees for all 3-chunk detectors.1 Binary tree representation of the detectors set generated from S.2 Conversion of a positive tree to a negative one.3 Diagram of the Detector Generation Algorithm.4 Diagram of the Positive-Negative Selection Algorithm.5 One node is reduced in a tree: a compact positive tree has 4 nodes (a) and its conversion (a negative tree) has 3 node (b).6 Detection time of NSA and PNSA.7 Nodes reduction on trees created by PNSA on Netflow dataset.8 Comparison of nodes reduction on Spambase dataset.1 Diagram of a algorithm to generate perfect rcbvl detectors set.1 Diagram of the algorithm to generate positive r-chunk detectors set. 55 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.2 A prefix DAG G and an automaton M .3 Diagram of the algorithm to generate negative r-contiguous detectors set.4 An automaton represents 3-contiguous detectors set.5 Comparison of ratios of runtime of r-chunk detector-based NSA to run- time of Chunk-NSA .6 Comparison of ratios of runtime of r-contiguous detector-based NSA to runtime of Cont-NSA. 64 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com vii List of Tables 1.1 Performance comparison of NSAs on linear strings and ring strings.1 Comparison of memory and detection time reductions.2 Comparison of nodes generation on Netflow dataset.1 Data and parameters distribution for experiments and results comparison.1 Comparison of our results with the runtimes of previously published algorithms.2 Comparison of Chunk-NSA with r-chunk detector-based NSA.3 Comparison of proposed Cont-NSA with r-contiguous detector-based NSA.1 Features for NIDS.2 Distribution of flows and parameters for experiments.3 Comparison between PSA2 and other algorithms.4 Comparison between ring string-based PSA2 and linear string-based PSA2. 76 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com viii Notation and Abbreviation Notation ` Length of data samples Sr Set of ring presentations of all strings in S |X| Cardinality of set X Σ An alphabet, a nonempty and finite set of symbols Σk Set of all strings of length k on alphabet Σ, where k is a positive integer.

Σ∗ Set of all strings on alphabet Σ, including an empty string. r Matching threshold Dpi Set of all positive r-chunk detectors at position i. Dni Set of all negative r-chunk detectors at position i. CHUNKp (S, r) Set of all positive r-chunk detectors.

CHUNK(S, r) Set of all negative r-chunk detectors. CONT(S, r) Set of all r-contiguous detectors. L(X) Set of all nonself strings detected by X. rcbvl r-contiguous bit with variable length.

Abbreviation AIS Artificial Immune System ACC Accuracy Rate ACO Ant Colony Optimization ANIDS Anomaly Network Intrusion Detection System BBNN Block-Based Neural Network Chunk-NSA Chunk Detector-Based Negative Selection Algorithm Cont-NSA Contiguous Detector-Based Negative Selection Algorithm DR Detection Rate DAG Directed Acyclic Graph FAR False Alarm Rate GA Genetic Algorithm HIS Human Immune System HIDS Host Intrusion Detection System IDS Intrusion Detection System LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com ix ML Machine Learning MLP Multilayer Perceptron NIDS Network Intrusion Detection System NS Negative Selection NSA Negative Selection Algorithm NSM Negative Selection Mutation PNSA Positive-Negative Selection Algorithm PSA Positive Selection Algorithm PSA2 Two-class Positive Selection Algorithm PSO Particle Swarm Optimization PSOGSA Particle Swarm Optimization-Gravitational Search Algorithm RNSA Real-valued NSA SVM Support Vector Machines TCP Transmission Control Protocol VNSA Variable length detector-based NSA LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com 1 INTRODUCTION Motivation Internet users and computer networks are suffering from rapidly increasing num- ber of attacks. In order to keep them safe, there is a need for effective security monitor- ing systems, such as Intrusion Detection Systems (IDS). However, intrusion detection has to face a number of different problems such as large network traffic volumes, im- balanced data distribution, difficulties to realize decision boundaries between normal and abnormal actions, and a requirement for continuous adaptation to a constantly changing environment. As a result, many researchers have attempted to use different types of approaches to build reliable intrusion detection system.

Computational intelligence techniques, known for their ability to adapt and to exhibit fault tolerance, high computational speed and resilience against noisy informa- tion, are hopefully alternative methods to the problem. One of the promising computational intelligence methods for intrusion detection that have emerged recently are artificial immune systems (AIS) inspired by the biolog- ical immune system. Negative selection algorithm (NSA), a dominating model of AIS, is widely used for intrusion detection systems (IDS) [55, 52]. Despite its successful application, NSA has some weaknesses: 1-High false positive rate (false alarm rate) and false negative rate, 2-High training and testing time, 3-Exponential relationship between the size of the training data and the number of detectors possibly generated for testing, 4-Changeable definitions of ”normal data” and ”abnormal data” in dynamic network environment [55, 79, 92].

To overcome these limitations, trends of recent works are to concentrate on complex structures of immune detectors, matching methods and hybrid NSAs [11, 94, 52]. Following trends mentioned above, in this thesis we investigate the ability of NSA to combine with other classification methods and propose more effective data LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com 2 representations to improve some NSA’s weaknesses. Scientific meaning of the thesis: to provide further background to improve per- formance of AIS-based computer security field in particular and IDS in general. Reality meaning of the thesis: to assist computer security practicers or experts implement their IDS with new features from AIS origin.

The major contributions of this research are: Propose a new representation of data for better performance of IDS; Propose a combination of existing algorithms as well as some statistical approaches in an uniform framework; Propose a complete and non-redundant detector representation to archive optimal time and memory complex- ities. Objectives Since data representation is one of the factors that affect the training and testing time, a compact and complete detector generation algorithm is investigated. The thesis investigates optimal algorithms to generate detector set in AIS. They help to reduce both training time and detecting time of AIS-based IDSs.

Also, it is regarded to propose and investigate an AIS-based IDS that can promptly detect attacks, either if they are known or never seen before. The proposed system makes use of AIS with statistics as analysis methods and flow-based network traffic as experimental data. Problem statements Since the NSA has some limitations as listed in the first section, this thesis concentrates on three problems: 1. The first problem is to find compact representations of data.

Objectives of this problem’s solution is not only to minimize memory storage but also to reduce testing time. The second problem is to propose algorithms that can reduce training time and testing time in compared with all existing related algorithms. LUAN VAN CHAT LUONG download : add luanvanchat@agmail. The third problem is to improve detection performance with respect to reduc- ing false alarm rates while keeping detection rate and accuracy rate as high as possible.

Solutions of these problems can partly improve first three weaknesses as listed in the first section. Regarding to the last NSAs’ weakness about changeable definitions of ”normal data” and ”abnormal data” in dynamic network environment, we consider it as a risk in our proposed algorithm and left it for future work. Logically, it is impossible to find an optimal algorithm that can both reduce time and memory complexities and obtain best detection performance. These aspects are always in conflict with each other.

Thus, in each chapter, we will propose algorithms to solve each problem quite independently. The intrusion detection problem mentioned in this thesis can be informally stated as: Given a finite set S of network flows which labeled with self (normal) or nonself (abnormal).

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ