Skip to Main Content
Once the computer system is intruded, the change from normal to abnormal is a gradual procedure. Setting up a calculating model based on danger theory for danger signal during the procedure will improve the accuracy and efficiency of artificial immune system (AIS) greatly. In this paper, the method of classified danger sensed (MCDS) for windows process intrusion detection based on danger theory is proposed. This method divides the processpsilas behavior parameters into two types: numeric and non-numeric types, using the functionpsilas difference and correlation coefficient to analyze the rule and relevance of numeric parameterspsila change, and evaluating the degree of danger of non-numeric parameters by analyzing the danger level and time relationship (TR) of data. Based on these methods, we establish calculating models of numeric and non-numeric danger signals separately, finally give the definition and calculating method of "danger degree".