Dendritic Cells for SYN Scan Detection

8 Pages Posted: 10 Sep 2016

See all articles by Julie Greensmith

Julie Greensmith

University of Nottingham - School of Computer Science

Uwe Aickelin

University of Melbourne - School of Computing and Information Systems

Date Written: January 1, 2007

Abstract

Artificial immune systems have previously been applied to the problem of intrusion detection. The aim of this research is to develop an intrusion detection system based on the function of Dendritic Cells (DCs). DCs are antigen presenting cells and key to the activation of the human immune system, behaviour which has been abstracted to form the Dendritic Cell Algorithm (DCA). In algorithmic terms, individual DCs perform multi-sensor data fusion, asynchronously correlating the fused data signals with a secondary data stream. Aggregate output of a population of cells is analysed and forms the basis of an anomaly detection system. In this paper the DCA is applied to the detection of outgoing port scans using TCP SYN packets. Results show that detection can be achieved with the DCA, yet some false positives can be encountered when simultaneously scanning and using other network services. Suggestions are made for using adaptive signals to alleviate this uncovered problem.

Keywords: artificial immune systems, Dendritic Cells, port scans, anomaly detection

Suggested Citation

Greensmith, Julie and Aickelin, Uwe, Dendritic Cells for SYN Scan Detection (January 1, 2007). Available at SSRN: https://ssrn.com/abstract=2831315 or http://dx.doi.org/10.2139/ssrn.2831315

Julie Greensmith

University of Nottingham - School of Computer Science ( email )

Jubilee Campus
Wollaton Road
Nottingham, NG8 1BB
United Kingdom

Uwe Aickelin (Contact Author)

University of Melbourne - School of Computing and Information Systems ( email )

Australia

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
24
Abstract Views
348
PlumX Metrics