Intrusion Detection Immune Network Algorithm

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional intrusion detection algorithms face challenges with handling noisy data and blurred boundaries, leading to low detection accuracy and high false alarm rates, especially when dealing with complex and dynamic network environments.

Innovation Solution

An improved immune network algorithm that initializes an antibody group, calculates affinities between antigens and antibodies, identifies duality antigens, determines boundary and neighbor antibody sets, clones and mutates antibodies, and simplifies the network to enhance detection accuracy and reduce false alarms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional clustering algorithms are used for intrusion detection, then the algorithm is simple to implement, but the detection accuracy is low and the algorithm is easily stuck in local optimum when applied to large-scale intrusion detection

Engineering Contradiction:
Improvealgorithm implementation simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent segments the intrusion detection process into multiple stages: data preprocessing with PCA, affinity calculation between antigens and antibodies, boundary antibody identification, and iterative optimization. This segmentation allows each stage to address specific aspects of the problem, improving overall detection accuracy while maintaining implementation feasibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic optimization through iterative affinity calculations and adaptive boundary antibody identification. The algorithm dynamically adjusts antibody affinities and reclassifies boundary antibodies in each iteration, enabling the system to escape local optima and improve detection accuracy over time

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If traditional immune network algorithm is used, then the algorithm has certain adaptability, but the processing efficiency is low and the detection accuracy is low due to inability to extract effective features from massive data

Engineering Contradiction:
Improvealgorithm adaptabilityVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies PCA dimensionality reduction as a preliminary action before the immune network algorithm processes the data. This preprocessing step extracts effective features from massive intrusion detection data, reducing computational complexity and improving processing efficiency while preserving the adaptability of the immune network algorithm

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes key parameters of the immune network algorithm, including the affinity calculation method and the boundary antibody identification threshold. These parameter changes optimize the balance between adaptability and processing efficiency, enabling the algorithm to handle massive data effectively

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If traditional immune network algorithm is used, then the algorithm can process intrusion detection data, but the network structure becomes complex and the training efficiency is low when dealing with noisy data and blurred boundaries

Engineering Contradiction:
Improvedata processing capabilityVSAvoidnetwork structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts and separately processes boundary antibodies from the main network structure. By identifying and handling boundary antibodies specifically through affinity comparisons with duality antigens, the algorithm simplifies the overall network structure while improving its ability to handle noisy data and blurred boundaries

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If traditional immune network algorithm is used, then the algorithm initializes antibody groups, but the detection accuracy is low and false alarm rate is high when the training set contains information noise or blurred boundaries

Engineering Contradiction:
Improvealgorithm initialization simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms through iterative affinity calculations and boundary antibody reclassification. In each iteration, the algorithm recalculates affinities, identifies new boundary antibodies, and reassigns them based on updated information. This feedback loop continuously improves detection accuracy and reduces false alarm rates even when the training set contains noise or blurred boundaries

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11762992B2Intrusion detection method based on improved immune network algorithm, and application thereof
Publication Date: 2023.09.19 HUBEI UNIV
  • US11762992B2 patent drawing
  • US11762992B2 patent drawing
  • US11762992B2 patent drawing

AI summary

The present disclosure belongs to the technical field of intrusion detection, specifically provides an intrusion detection method based on an improved immune network algorithm, and an application thereof The method includes: S1, initializing an antibody group; S2, calculating affinities between antigens and antibodies; S3, searching for a pair of inhomogeneous antigens which have the highest affinities and referred to as a duality antigen; S4, determining a boundary antibody set C; S5, determining a neighbor antibody set; S6, cloning and mutating, according to the affinities, obsolete antibodies to update a subnetwork to which the antigens belong; S7, calculating an average affinity between the antibodies in the boundary antibody set C and the antigens in the duality antigen; and S8, inhibiting the network, and simplifying the network to output a result network subset. The solution has relatively high detection accuracy and relatively low false alarm rate.