Dynamic Updating of Profiles for an Immunity-Based Anomaly Detection System

  • Authors:
  • Takeshi Okamoto;Yoshiteru Ishida

  • Affiliations:
  • Dept. of Network Engineering, Kanagawa Institute of Technology, Kanagawa, Japan 243-0292;Dept. of Knowledge-Based Information Engineering, Toyohashi University of Technology, Tempaku, Toyohashi, Japan 441-8580

  • Venue:
  • KES '08 Proceedings of the 12th international conference on Knowledge-Based Intelligent Information and Engineering Systems, Part III
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Our immunity-based anomaly detection system aims to detect anomalous behavior of users on a computer. To improve the detection accuracy, we introduced the framework of dynamically updating profiles into our system. Our system enables agents to update not only self profiles, but also nonself profiles. Briefly, our system enables agents to adapt to new behavior of the original users and of others. The receiver operating characteristic (ROC) analysis of our system indicated that the updating of both profiles markedly decreased both the false alarm rate and the missed alarm rate.