An intrusion detection model based on biological immune principle and one-class classification technology is proposed. The one-class classification technology named support vector domain description (SVDD) is applied to the proposed model. Simple multi-dimension feature vectors of network packets are mapped into high dimension feature space. The description models of the antibody and the self set are constructed. The evolution process of antibodies is described with math language. The theoretical analysis shows that the proposed model can detect network attack effectively, and unknown network attacks can be detected.
Read full abstract