<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>An Autonomic Computing System based on a Rule-based Policy Engine and Artificial Immune Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Rahmira Rufus</string-name>
          <email>rsrufus@aggies.ncat.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>William Nick</string-name>
          <email>wmnick@aggies.ncat.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Joseph Shelton</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Albert Esterline</string-name>
          <email>esterlin@ncat.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer Science, North Carolina A&amp;T State University</institution>
          ,
          <addr-line>Greensboro, NC 27411</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <fpage>105</fpage>
      <lpage>108</lpage>
      <abstract>
        <p>Autonomic computing systems arose from the notion that complex computing systems should have properties like those of the autonomic nervous system, which coordinates bodily functions and allows attention to be directed to more pressing needs. An autonomic system allows the system administrator to specify high-level policies, which the system maintains without administrator assistance. Policy enforcement can be done with a rule based system such as Jess (a java expert system shell). An autonomic system must be able to monitor itself, and this is often a limiting factor. We are developing an automatic system that has a policy engine and uses Artificial Immune Systems (AISs) to sense its environment and to monitor its components and performance. AISs emulate the natural immune system to defend the body against external malicious entities. The proposed system monitors itself without human intervention and thus addresses the problem of systems complexity.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>With more systems and devices networked together, more
system administrators are required to monitor and maintain
these networks, and maintenance becomes costly and time
consuming. Yet it may not be clear how a complex
system may manage itself in the absence of a human. We
here report on an autonomic system we are developing for
a network-connected computer system that self-manages by
using mechanisms similar to the autonomic nervous
system of the body to achieve the so-called self-CHOP
properties: self-configuring, self-healing, self-optimizing, and
self-protecting. A rule-based policy enforcement engine is
used (like the body’s hypothalamus) to regulate the
autonomic system, and the system has artificial immune systems
(AIS) that mimic the functions of the sensory and motor
subsystems.</p>
      <p>The remaining sections of this paper are organized as
follows. The next section provides background on autonomic
computing, AISs, and rule-based systems. We then discuss
the motivation for implementing an AIS. There follows a
section that presents the architecture of our autonomic
system. This is followed by the AIS sensoring agent section,
where we describe how the AIS aids the autonomic system
with its self-CHOP capabilities via anomaly detection. The
context monitor is then described, followed by a section
describing how the self-CHOP properties are realized by our
system. The final section presents the conclusion and future
work.</p>
    </sec>
    <sec id="sec-2">
      <title>Background</title>
    </sec>
    <sec id="sec-3">
      <title>Autonomic Computing</title>
      <p>
        IBM, in a 2001 manifesto, compared complex computing
systems to the human body, which has an autonomic nervous
system that removes the tasks of consciously coordinating
bodily functions
        <xref ref-type="bibr" rid="ref11">(Huebscher and McCann 2008)</xref>
        . Complex
computing systems should have autonomic properties that
independently take care of tasks of regular maintenance and
optimization tasks, thus reducing the workload on the
system administrator.
      </p>
      <p>
        IBM also articulated the four self-CHOP properties.
Selfconfiguration is defined as components and systems being
configured as per high-level policies
        <xref ref-type="bibr" rid="ref12">(Kephart and Chess
2003)</xref>
        . When a component is introduced into a system, it is
incorporated seamlessly, and the rest of the system adapts to
the presence of the new component. With self-optimization,
components and systems continually seek to improve their
performance and efficiency. Self-healing is defined as a
system automatically detecting, diagnosing, and repairing
problems in software and hardware. Finally, self-protection
is defined as a system being able to automatically defend
against malicious attacks or cascading failures. Kephart et
al.
        <xref ref-type="bibr" rid="ref13">(Kephart and Walsh 2004)</xref>
        came up with three types of
policies for autonomic computing: 1) action policies, 2) goal
policies, and 3) utility function policies. Action policies
specify what actions should be taken based on the current
state of the system. A goal policy specifies either a desired
state or a set of criteria for a desired state. Utility function
policies are objective functions that provide a utility value
for each possible state.
      </p>
    </sec>
    <sec id="sec-4">
      <title>Artificial Immune Systems</title>
      <p>
        The natural immune system is a defense mechanism that can
learn about foreign entities that enter the body and respond
to them by creating defensive antibodies. This concept has
been artificially simulated for intrusion detection, resulting
in an approach known as an artificial immune system (AIS)
        <xref ref-type="bibr" rid="ref10 ref7">(Hofmeyr and Forrest 2000)</xref>
        . Similar to the biological
immune system, the goal of an AIS is to distinguish between
self and non-self entities. The natural immune system that
this system imitates depicts self as a cell that is innate or
safe for the body while non-self is not. One can associate
this mapping with detecting or sensing what is as opposed
to what is not; this mapping is also known as a detector.
      </p>
      <p>
        AISs have also been applied to the problems of fault
diagnostics, fraud detection and detecting viruses
        <xref ref-type="bibr" rid="ref6">(DasGupta
1993)</xref>
        . There are a few methods for using an AIS. One is the
negative selection algorithm (Forrest et al. 1994).This
technique randomly generates a set of detectors that are trained
to match any non-self entities for any system and not match
any self entities. More specifically, the detectors are first
applied on a set of self entities and the ones that detect the self
entities are discarded. The idea is that, if a detector does
not match self, it has a better chance of detecting non-self,
which would be any anomaly in the system. The surviving
detectors can then be applied on non-self to observe how
much of the set can be detected.
      </p>
    </sec>
    <sec id="sec-5">
      <title>Rule-Based Systems</title>
      <p>
        The classical application of rule-based systems is in expert
systems, which typically use a human experts knowledge for
solving real world problems
        <xref ref-type="bibr" rid="ref2">(Abraham 2005)</xref>
        . This expert
knowledge is often expressed in the terms of rules. These
rules and data constitute a rule-based expert systems. Such
systems have played a role in modern artificial intelligence
and other applications such as fault monitoring. The
Ponder rule-based policy language
        <xref ref-type="bibr" rid="ref3">(Bradshaw, Uszok, and
Montanari 2014)</xref>
        is the broadest and most widely used policy
language.Its policies are rules that define system behavior
choices that reflect on objectives set by system managers.
Other rule-based policy enforcement systems use the
eventcondition-action rule paradigm. An example of this is Bell
Labs’ policy description language, in which a policy is a
function that maps a series of events into a set of actions.
      </p>
      <p>
        Carey et al. created a composite service execution engine
for composing web services
        <xref ref-type="bibr" rid="ref13 ref5">(Carey, Lewis, and Wade 2004)</xref>
        .
The policy engine for this execution engine uses the Jess rule
engine
        <xref ref-type="bibr" rid="ref9">(Friedman-Hill 2013)</xref>
        . The rules are executed to
refine goals into service policies. Before the policy engine can
execute, additional information is required such as the name
of the service and the finite state machine (FSM) models
for each of the constituted services. Goals are refined by
Jess rules triggered when the state used in high-level policy
matches the state in the FSM of the composite service.
      </p>
    </sec>
    <sec id="sec-6">
      <title>Requirements</title>
      <p>We aim for a system capable of adapting to unforeseen
occurrences in the operating environment. This includes
adjusting to situations in a proactive manner as well as
reactively supporting system recovery. Here pro-action amounts
to perceiving danger then preempting harm or any
compromised system state. Fault tolerance in the operating
environment permits system execution to continue without
interruption, while preempting failure from a system-wide
perspective presupposes the occurrence of a compromised system
component or operation.</p>
      <p>
        Anomaly detection can be a key component to
properly assessing whether events are uncharacteristic of a
system’s configuration
        <xref ref-type="bibr" rid="ref10 ref7">(De Castro and Von Zuben 2000)</xref>
        .
Furthermore, accompanying this detection method with a
response procedure that reduces the damage of the
compromised component is crucial, but also crucial is
simultaneously permitting uncompromised system components to
continue. One goal of this research is to provide a sensoring
component that promotes the self-CHOP requirements for
an autonomic system.
      </p>
      <p>
        One immunity-inspired algorithm of interest focuses on
danger theory, which extends the role of the innate
immune system for discriminating between ‘self’ and
‘nonself’ but employs the acquired immune system to react to
danger
        <xref ref-type="bibr" rid="ref4">(Brownlee 2011)</xref>
        . Sensing danger lets a system
protect, recover or heal, optimize and determine whether a
reconfiguration assessment is necessary. Unlike Fail2ban, our
system will learn new malicious and unwanted traffic to
protect itself from malicious and unwanted traffic in the future.
      </p>
    </sec>
    <sec id="sec-7">
      <title>System Architecture</title>
    </sec>
    <sec id="sec-8">
      <title>AIS Sensor Agents</title>
      <p>We here discuss how the AISs contribute to the self-CHOP
properties. Note that sometimes we refer to a single AIS
while other times we partition the functionality among
several AISs. Although we refer to sensing, note that the AISs
detect both external and internal state. The AIS sensoring
apparatus will consist of detector populations that
monitor system activity as does a network sniffer or
intercepting proxy. The AIS component will deploy detectors that
compare system activity against normal system behavior.
The detection methods behave as intrusion detection
systems (IDSs) that detect system irregularities not stated in the
innate system configuration. The detection method can also
adapt to changes in the system.</p>
      <p>The detector set will become a new feature vector for
detecting danger in the system. The new vector will allow the
system to recognize system behavior that has been
previously labeled as dangerous. The new danger vector is then
propagated throughout the system to scan for stress levels
that are approaching this danger state.</p>
      <p>Each round, the AIS will acquire more knowledge about
the operating environment via the detector populations. The
cloning process allows one generation to be more adept than
the previous. The acquired immunity that aids the AIS in
determining the health of the system is expressed via the
number of danger vectors that have been detected and mitigated
properly, with more emphasis on the mitigation process.</p>
      <p>Following the detection of a stress level threshold being
met, the policy engine will determine whether the system is
in danger based upon the signal that the AIS found to
indicate danger. If danger is confirmed, then the policy engine
will determine what the system needs to repair or heal itself.
For each consecutive detection round, the AIS will monitor
the healing process by executing a subset of detectors for
repair monitoring.</p>
      <p>
        The system will adapt to the configuration expected of
systems and components as per high-level policies during
self-configuration
        <xref ref-type="bibr" rid="ref12">(Kephart and Chess 2003)</xref>
        . Conversely,
within the configuration assessment module, the AIS will
initially transmit a response to the policy engine that the
need for repair or healing is not foreseeable. During the
healing or repair process, the repair subset monitors the
healing of the system via the change from affinity to a danger
vector to the self set. Excessive danger is the signal to the
policy engine to determine whether the system should limit
the usage of the system component because the component
might cause other components to be compromised. To
increase the fault tolerant capabilities for the autonomic
system, the AIS will monitor the affinity to danger or self for all
system components involved or related to this configuration
assessment.
      </p>
    </sec>
    <sec id="sec-9">
      <title>Context Monitor</title>
      <p>
        The environment of a computer system can undergo changes
for any number of reasons. To deal with this, one
exploits context awareness, a computer sensing and reacting
to changes in its environment
        <xref ref-type="bibr" rid="ref1">(Abowd et al. 1999)</xref>
        . The
environment that is monitored by some context-aware device is
generally external; however, there is no reason that the
environment cannot be the internal workings of a system. There
are several consistent workings of any system that are
consistent, such as CPU usage, amount of memory available,
and network traffic to name a few.
      </p>
    </sec>
    <sec id="sec-10">
      <title>Rule-based Policy Engine</title>
      <p>
        For our rule-based policy engine, we used Jess (Java
Expert System Shell)
        <xref ref-type="bibr" rid="ref9">(Friedman-Hill 2013)</xref>
        . The policies use
if-then rules as is standard with Jess. The variables in the
rules are values provided by the AIS and the context
monitor. The rule-based system will control switches and various
resources. The sensor data from the AIS and the context
monitor will be fused using the Dempster-Shafer theory of
evidence
        <xref ref-type="bibr" rid="ref15">(Shafer 1976)</xref>
        . Based on the fused data, policies
that are appropriate will be executed.
      </p>
      <p>One of the purposes of our proposed system is intrusion
detection. With this in mind, there are policies that are
focused on this activity. For one thing, if packets from the
network come in and the timestamp of these packets are a
certain time away from the system’s current time, a flag will
be raised. If continuous traffic is coming from one specific
IP address, it could be indicative of a Denial-of-Service
attack. In this case, the system may block packets from that
particular IP address. For any input coming into the system,
it is assumed that the input is in a standard format.
However, if the input appears to be irregular, such as a password
having many symbols not numerical or alphabetical, then a
warning flag may be raised. There are also policies related
to internally monitoring the system. The system should run
fairly consistently, where the CPU usage may spike or idle
depending on certain actions occurring on the system. If
there are times when the CPU spikes or peaks and none of
the activities that normally causes this are occurring, then
the system may take actions to run a diagnostics check on
it. If enough memory is consumed, the system may run a
heuristic to delete items that it considers to no longer be
necessary. The AISs in the machine are developing detectors to
detect anomalies externally and internally. The policies can
have additional steps that state that if it catches anything the
detectors from the AISs do not, it will prompt the AISs to
adjust its detector creation strategy.</p>
      <p>enough memory is consumed, the system may run a
heuristic to delete items that it considers to no longer be
necessary. The AISs in the machine are developing detectors to
detect anomalies externally and internally. The policies can
have additional steps that state that if it catches anything the
detectors from the AISs do not, it will prompt the AISs to
adjust its detector creation strategy.</p>
      <p>
        Within any automated system, faults can occur. Faults can
be described as unexpected changes from the normal system
condition. The area of research dedicated to detecting faults
is referred to as the Abnormal Event Management (AEM)
in research done by Laurentys et al.
        <xref ref-type="bibr" rid="ref14">(Laurentys et al. 2010)</xref>
        .
More specifically, the AEM deals with detecting, diagnosing
and correcting abnormal conditions in real-time. An AIS can
develop detectors that have a great information processing
capability, pattern recognition and learning ability. These
abilities can be applied towards creating detectors that can
detect faults and take appropriate action. In the scope of our
problem, the faults would be internal such as if something
goes wrong with disk mirroring, or memory swapping from
the disk. The self set of a detector would be the “normal”
state of the system, and non-self would be anything that is
different enough from the baseline of the system.
      </p>
    </sec>
    <sec id="sec-11">
      <title>Realization of the Self-CHOP Properties</title>
      <p>A major aspect of protection is sensing attempted intrusion,
which is a standard task for AISs, detecting “self” and
“nonself.” We can generalize this function to perceiving danger
(in the environment) in general and perhaps even to
recognizing a need to adapt to a change in the environment. The
general notion is that of monitoring the environment to
protect self. The intent is that an AIS will identify a threat and
characterize it sufficiently so that the policy engine may
activate resources as per the applicable policies. The expert
system may consult with AISs in the course of enforcing a
policy.</p>
      <p>In a similar vein, we can have the AISs detect when the
system is not “itself” and in need of repair; this is the heal
CHOP attribute, and what is monitored is self. The role of
the AIS here is to identify faulty behavior and to characterize
it so that the expert system may activate resources as per the
applicable policies. Again, the policy engine may consult
with AISs in the course of enforcing a policy.</p>
      <p>This vigilance regarding the system’s own behavior may
extend to self-optimization if we have a baseline reading of
system behavior. An AIS would help us distinguish
acceptable patterns that deviate from this pattern (as when some
resource is accessed) from unacceptable patterns. Something
similar could address self-configuration. The most obvious
occasions for self-configuration, however, are where a new
device is attached. In such cases, a simple signal from a
context monitor would suffice to provide the policy engine
all the information needed to apply policies.</p>
    </sec>
    <sec id="sec-12">
      <title>Conclusion &amp; Future Work</title>
      <p>We have sketched the autonomic system we are developing
that uses artificial immune systems (AISs) augmented with
a context monitor to provide data to a rule-based policy
engine. The architecture is conceptualized as the AISs and
context monitor providing sense data to the policy engine,
but not that the data is also from the internal state of the
system. We discussed how the system supports the self-CHOP
properties: self configuring, self-healing, self-optimizing,
and self-protecting.</p>
      <p>We are implementing our autonomic architecture on a
stock workstation that is attached to the Internet (inviting
intruders) and to which we can attached multiple accessories
(requiring self-configuration). In the future, we plan to
investigate autonomic cyberphysical systems. In the future,
we shall look into other biological metaphors and implement
some into our system.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Abowd</surname>
            ,
            <given-names>G. D.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Dey</surname>
            ,
            <given-names>A. K.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Brown</surname>
            , P. J.; Davies,
            <given-names>N.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Smith</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ; and Steggles,
          <string-name>
            <surname>P.</surname>
          </string-name>
          <year>1999</year>
          .
          <article-title>Towards a better understanding of context and context-awareness</article-title>
          .
          <source>In Handheld and ubiquitous computing</source>
          ,
          <volume>304</volume>
          -
          <fpage>307</fpage>
          . Springer.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Abraham</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>2005</year>
          .
          <article-title>Rule-based expert systems</article-title>
          .
          <source>Handbook of measuring system design.</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Bradshaw</surname>
            ,
            <given-names>J. M.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Uszok</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ; and Montanari,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <surname>Brownlee</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <year>2011</year>
          .
          <article-title>Clever algorithms: nature-inspired programming recipes</article-title>
          .
          <source>Jason Brownlee.</source>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <surname>Carey</surname>
            ,
            <given-names>V. K.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Lewis</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ; and
          <string-name>
            <surname>Wade</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <year>2004</year>
          .
          <article-title>Automated policy-refinement for managing composite services</article-title>
          .
          <source>MZones White Paper June</source>
          <volume>4</volume>
          :
          <fpage>114</fpage>
          -
          <lpage>130</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>DasGupta</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <year>1993</year>
          .
          <article-title>An overview of artificial immune systems and their applications</article-title>
          . Springer.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <surname>De Castro</surname>
            ,
            <given-names>L. N.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Von Zuben</surname>
            ,
            <given-names>F. J.</given-names>
          </string-name>
          <year>2000</year>
          .
          <article-title>Artificial immune systems: Part i-basic theory and applications</article-title>
          . Universidade Estadual de Campinas, Dezembro de,
          <source>Tech. Rep</source>
          <volume>210</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          1994.
          <article-title>Self-nonself discrimination in a computer</article-title>
          . In null,
          <volume>202</volume>
          . Ieee.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <surname>Friedman-Hill</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          <year>2013</year>
          .
          <article-title>Jess, the rule engine for the java platform</article-title>
          .
          <source>Java Expert System Shell</source>
          , http://jessrules.com, United States.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <surname>Hofmeyr</surname>
            ,
            <given-names>S. A.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Forrest</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <year>2000</year>
          .
          <article-title>Architecture for an artificial immune system</article-title>
          .
          <source>Evolutionary computation 8</source>
          (
          <issue>4</issue>
          ):
          <fpage>443</fpage>
          -
          <lpage>473</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <surname>Huebscher</surname>
            ,
            <given-names>M. C.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>McCann</surname>
            ,
            <given-names>J. A.</given-names>
          </string-name>
          <year>2008</year>
          .
          <article-title>A survey of autonomic computingdegrees, models, and applications</article-title>
          .
          <source>ACM Computing Surveys (CSUR) 40</source>
          (
          <issue>3</issue>
          ):
          <fpage>7</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          <string-name>
            <surname>Kephart</surname>
            ,
            <given-names>J. O.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Chess</surname>
            ,
            <given-names>D. M.</given-names>
          </string-name>
          <year>2003</year>
          .
          <article-title>The vision of autonomic computing</article-title>
          .
          <source>Computer</source>
          <volume>36</volume>
          (
          <issue>1</issue>
          ):
          <fpage>41</fpage>
          -
          <lpage>50</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          <string-name>
            <surname>Kephart</surname>
            ,
            <given-names>J. O.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Walsh</surname>
            ,
            <given-names>W. E.</given-names>
          </string-name>
          <year>2004</year>
          .
          <article-title>An artificial intelligence perspective on autonomic computing policies</article-title>
          .
          <source>In Policies for Distributed Systems and Networks</source>
          ,
          <year>2004</year>
          .
          <article-title>POLICY 2004</article-title>
          .
          <article-title>Proceedings</article-title>
          . Fifth IEEE International Workshop on, 3-
          <fpage>12</fpage>
          . IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          <string-name>
            <surname>Laurentys</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Ronacher</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ; Palhares,
          <string-name>
            <given-names>R. M.</given-names>
            ; and
            <surname>Caminhas</surname>
          </string-name>
          ,
          <string-name>
            <surname>W. M.</surname>
          </string-name>
          <year>2010</year>
          .
          <article-title>Design of an artificial immune system for fault detection: a negative selection approach</article-title>
          .
          <source>Expert Systems with Applications</source>
          <volume>37</volume>
          (
          <issue>7</issue>
          ):
          <fpage>5507</fpage>
          -
          <lpage>5513</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <string-name>
            <surname>Shafer</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          <year>1976</year>
          .
          <article-title>A mathematical theory of evidence</article-title>
          , volume
          <volume>1</volume>
          . Princeton university press Princeton.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>