Technical Report: DCC-2006-04

Towards a new Immunity-Inspired Intrusion Detection Framework

Mário J. Antunes

Departamento de Ciência de Computadores
Faculdade de Ciências da Universidade do Porto
E-mail: mario.antunes@estg.ipleiria.pt

and

Manuel E. Correia


Departamento de Ciência de Computadores
Faculdade de Ciências da Universidade do Porto
E-mail: mcc@dcc.fc.up.pt
October 2006

Abstract

In this document we introduce a novel framework for behaviour based Network Intrusion Detection Systems (NIDS). Its main goal is the application of theoretical immunological concepts to provide adaptability to the normality of the network behaviour, based on memory and learning from previous attacks. We present some important principles and concepts relevant to the description and categorization of Intrusion Detection Systems (IDS), and then describe the main benefits that can be obtained from an Artificial Immune System (AIS) approach for IDS. We conclude by proposing a novel extension to the Common Intrusion Detection Framework (CIDF) capable of accommodating our initial goals.