Paper
19 May 2009 An immunological model for detecting bot activities
Md E. Karim, Vir V. Phoha, Md A. Sultan
Author Affiliations +
Abstract
We develop a hierarchical immunological model to detect bot activities in a computer network. In the proposed model antibody (detector)-antigen (foreign object) reactions are defined using negative selection based approach and negative systems-properties are defined by various temporal as well as non-temporal systems features. Theory of sequential hypothesis testing has been used in the literature for identifying spatial-temporal correlations among malicious remote hosts and among the bots within a botnet. We use it for combining multiple immunocomputing based decisions too. Negative selection based approach defines a self and helps identifying non-selves. We define non-selves with respect to various systems characteristics and then use different combinations of non-selves to design bot detectors. Each detector operates at the client sites of the network under surveillance. A match with any of the detectors suggests presence of a bot. Preliminary results suggest that the proposed model based solutions can improve the identification of bot activities.
© (2009) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Md E. Karim, Vir V. Phoha, and Md A. Sultan "An immunological model for detecting bot activities", Proc. SPIE 7352, Intelligent Sensing, Situation Management, Impact Assessment, and Cyber-Sensing, 73520U (19 May 2009); https://doi.org/10.1117/12.819073
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Network security

Sensors

Databases

Systems modeling

Detection and tracking algorithms

Chemical elements

Computer networks

Back to Top