A Danger-Theory-Based Abnormal Traffic Detection Model in Local Network
Wang Xiu-ying, Xiao Lizhong, Zhiqing Shao · 2008
To solve the problem that abnormal traffic including Internet worm and P2P downloading has occupied the LAN’s bandwidth, a danger-theory-based model to detect anomaly traffic in LAN is presented in this paper. The definition is given, in this paper, to such terms as dangerous signal, antigens, antibodies and memory antibodies. Besides, matching rule between antigen and antibody is improved. Experiments show the outstanding performance of the proposed model in real-time property, high detection rate and unsupervised learning.