Sensors 2009, 9(11), 9175-9195; doi:10.3390/s91109175

An Immunity-Based Anomaly Detection System with Sensor Agents

1,* email and 2email
Received: 30 June 2009; in revised form: 5 November 2009 / Accepted: 9 November 2009 / Published: 18 November 2009
(This article belongs to the Special Issue State-of-the-Art Sensors Technology in Japan)
This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
Abstract: This paper proposes an immunity-based anomaly detection system with sensor agents based on the specificity and diversity of the immune system. Each agent is specialized to react to the behavior of a specific user. Multiple diverse agents decide whether the behavior is normal or abnormal. Conventional systems have used only a single sensor to detect anomalies, while the immunity-based system makes use of multiple sensors, which leads to improvements in detection accuracy. In addition, we propose an evaluation framework for the anomaly detection system, which is capable of evaluating the differences in detection accuracy between internal and external anomalies. This paper focuses on anomaly detection in user’s command sequences on UNIX-like systems. In experiments, the immunity-based system outperformed some of the best conventional systems.
Keywords: immunity-based system; anomaly detection; intrusion detection; sensor agent; hidden Markov model; receiver operating characteristics
PDF Full-text Download PDF Full-Text [370 KB, uploaded 21 June 2014 02:51 CEST]

Export to BibTeX |

MDPI and ACS Style

Okamoto, T.; Ishida, Y. An Immunity-Based Anomaly Detection System with Sensor Agents. Sensors 2009, 9, 9175-9195.

AMA Style

Okamoto T, Ishida Y. An Immunity-Based Anomaly Detection System with Sensor Agents. Sensors. 2009; 9(11):9175-9195.

Chicago/Turabian Style

Okamoto, Takeshi; Ishida, Yoshiteru. 2009. "An Immunity-Based Anomaly Detection System with Sensor Agents." Sensors 9, no. 11: 9175-9195.

Sensors EISSN 1424-8220 Published by MDPI AG, Basel, Switzerland RSS E-Mail Table of Contents Alert