<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>CEUR Workshop Proceedings</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.18287/1613</article-id>
      <title-group>
        <article-title>RESEARCH THE BEHAVIOR OF ELEMENTS IN ARTIFICIAL IMMUNE SYSTEM FOR INTRUSION DETECTION SYSTEMS IN INFORMATION NETWORKS</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>M.E. Burlakov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>M.N. Osipov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Samara National Research University</institution>
          ,
          <addr-line>Samara</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <volume>1638</volume>
      <fpage>895</fpage>
      <lpage>901</lpage>
      <abstract>
        <p>This paper proposes for watching the artificial immune system. The definitions the basic element and the element with the memory like the part of artificial immune system in intrusion detection systems are described. The metric between elements with the limit measure is set. This metric is called affinity and the limit measure is called affinity threshold. The definitions of clone and mutation operations are set. Besides, the behavior between basic elements and elements with the memory on using clone and mutation operations in artificial immune system is researched.</p>
      </abstract>
      <kwd-group>
        <kwd>artificial immune system</kwd>
        <kwd>information network</kwd>
        <kwd>intrusion detection system</kwd>
        <kwd>clone operation</kwd>
        <kwd>mutation operation</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>Today there is important task of classifying the data and messages transmitted from
the sender to the recipient through different systems in modern information
infrastructure (mail, web, irq и т.д.). This problem solved by using either non-adaptive
(methods of attack graphs scenarios, methods of analysis of the state systems, expert
systems, methods on specifications, signature-based methods, etc.) or adaptive (artificial
neural networks, artificial immune algorithms, genetic algorithms, etc.) methods
[115].</p>
      <p>As a part of information system the problem of classification the messages is reduced
to task of classifying incoming data to definite class (for example, by relevance, by
sender, by content and volume).</p>
      <p>Today, in analyzing and classifying messages problem the most actual solution is
using the classification data by it content. If we have no any information about data
source it’s possible to determine the class which this data can be applied with a
cer1. Reliable (actual, legitimate, and so on) class of data information;
2. Non-reliable (irrelevant, illegitimate, etc.) class of data information.
The reliable (legitimate) information is a set of data which doesn’t include any
threat in terms of availability, integrity and confidentiality for information system.
Otherwise, the information is called non-reliable (illegitimate). Any anti-spam system
or software and hardware anti-virus protection is classic example of such
classification, because the information is classified by its content for two classes: reliable and
non-reliable.</p>
      <p>As said before, there are a large number of both adaptive and non-adaptive algorithms
can classify the data blocks (emails) by its content. In [19] there is proposition which
solves the problem by using two-classification artificial immune system.</p>
    </sec>
    <sec id="sec-2">
      <title>Two-classification artificial immune system</title>
      <p>Two-classification artificial immune system (2CAIS) is an adaptive algorithm with
the teacher, which allows to classify the data blocks (emails) for two classes: reliable
class of messages and the non-reliable class of messages.</p>
      <p>The algorithm of two-classification artificial immune system was produced as an
analogue of the biological immune system. The β-element (base element) and a
βmelement (element with memory) are the basic definitions of 2CAIS. This elements are
analogs of B-lymphocyte and B-lymphocyte with the memory in biological systems.
B-lymphocyte and B-lymphocyte with memory, from a biological point of view, are
"security flag". If this flag is changed the signal about it is created and the
lymphocytes are generated by the body. The lymphocytes are deal with the (antigens). If the
lymphocyte destroys a particular threat successfully or responds it with the higher
probability, immune system transfers this B-lymphocyte to B-lymphocyte with the
memory. Immune system transforms B-lymphocytes to B-lymphocyte with the
memory using the presence of a weighting parameter. The more effective lymphocyte
makes its functions the higher its "weight" and vice versa. If the lymphocyte does not
provide effective kind of threat detection the immune system reduces the value of
weight parameter until it reaches the point where it can be removed from the system
finally.</p>
      <p>Similarly, B-lymphocyte is a β-element and B-lymphocyte with the memory is
βmelement in two-classification artificial immune system.</p>
      <p>Also, similarly, the age (power, weight) is the main parameter of β-element. The age
is a non-zero value, which characterizes the element weight. It fulfills the "death"
condition of elements. If its value becomes equal zero the element is removed from
the system. Another words, the age parameter shows the efficiency of elements. Also
there are mutation and cloning operations in 2CAIS.</p>
      <p>
        The mutation operation is a process of changing the β-element structure randomly.
The age of the β-element is finite and the process of mutation affects only a certain
number of entities. The measure of mutation is set on initializing stage 2CAIS
algorithm. The mutating operation (Mutating) is equivalent to write:
Mutating()  i   j ,     j , |  |  |  |, i  m  j ,
m [0,1]
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
where crossing sign is equivalent to the replacement operation;
α – set of entities from the β-element;
m – mutation rate.
      </p>
      <p>The cloning operation (Cloning (β)) is used for creating new β-elements in artificial
immune system. This operation is applied when the mutation operation is finished.
The cloning copies new mutate β-elements to current β-element set. The cloning
coefficient is an important parameter of cloning operation. It shows how much elements
will be created relative to the original.</p>
      <p>Thus, the mutation operation creates new β-elements which potential to identify new
threats. The cloning operation clones these elements to system.</p>
      <p>These operations provide the variability between βm-elements and a simple
βelements. The variability is the process which considers βm-element like the element
with the memory. The βm-element is the most well-established "cast" the threat that it
is able to effectively detect. Simple β-element is produced by a combination of a
random selection of words from the emails or datasets with the applying of cloning and
mutation operations. The βm-element is derived from iterative measure of
effectiveness β-element working in a set of emails.</p>
      <p>The distance (metrics) between the β-elements is calculated by using the affinity
definition.</p>
      <p>In 2CAIS the affinity of the elements defined as the ratio between the number of
common entities, which are composed of these elements to norm. The norm of two
elements is the minimum number of entities that make up each of the elements.
Therefore, the affinity (Affinity or α) may be expressed as the following equation:
Affinity(1,2 )  (1,2 ) </p>
      <p>Count(1i 2 )</p>
      <p>j , i  j
min(| 1i |, | 2j |)
where i, j – the order of the entities in the element;
Count – a function of the number of intersections of the elements;
|βj| – element capacity (the number of entities in the elements).</p>
      <p>If the value of the affinity between the antigen (threat or potential message from the
class of non-reliable information) and any β-element is above some threshold value
(threshold affinity), then it means that the β-element recognizes the threat. After that,
the system mark this data block (email) as a non-reliable, otherwise the data block is
marked as reliable.</p>
      <p>On the one hand, the affinity allows to detect the threat and thus carry out the process
of the primary classification. On the other hand, there is a question to research the
relationship between the processes of creating of β-elements and βm-elements. In other
words, there is a task that requires to explore the relationship between basic (simple)
β-elements and βm-elements with the memory which have the affinity metrics cloning
and mutation operations through the problem of classification data block (emails) into
two classes: reliable information class and non-reliable information class of messages.
To solve the task of finding the relationship between β-elements and βm-elements
prove Proposition 1.</p>
      <sec id="sec-2-1">
        <title>Proposition 1.</title>
        <p>For each ε &gt; 0 exists [0,1] such that |β| = λ|βm |.</p>
      </sec>
      <sec id="sec-2-2">
        <title>Proof</title>
        <p>Let introduce some notation.</p>
        <p>Consider the initial set of messages (emails, data blocks) S. β-elements initialized
from S, |S| = s, s&gt;0 and sN . Let k – the age if β-element, and n – the threshold
when   m (affinity threshold), and r = n-k, r&gt;0, the difference between them.
There are is1(k ) – elements (words in email) when the system is initialized.
Let α – the value of the affinity function Affinity() for two elements. Pα – probability
of appearing two β-elements which have the affinity distance greater than or equal to
α, pi – its corresponding value. Let l the cloning coefficient in function Cloning(β)
(hereinafter briefly denoted by C(β) function). Let m the mutation coefficient which
corresponds the probability characteristics of new β-elements in Mutating(β)
(hereinafter briefly denoted as a function of M(β)).</p>
        <p>General algorithm of producing β-element and βm-elements consists of several steps:
Step 1. Initialization β-element set from the S set;
Step 2. Application the mutation and cloning functions to β-element set;
Step 3. Calculate the probability Pα for getting β-element set;
Step 4. Go to Step 2.</p>
        <p>Consider the process iteratively. In Steps 1 and 2 the set of β-elements applied the
cloning and mutation operation:</p>
        <p>
          s
C (M ( (k ))) (
          <xref ref-type="bibr" rid="ref3">3</xref>
          )
i1
In Step 3, for each β-element from β-element calculated the probability Pα. After that,
there is new set of β-elements with the different age due to affinity threshold. Next, go
to Step 2. Finally, the process consists of a finite set of iterations.
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>Iteration 1.</title>
        <p>
          s b11s1 b12 s1b11
M1  C(M (i1(k ))) | P  i11i1 (k  1) i21i2 (k  1) (
          <xref ref-type="bibr" rid="ref4">4</xref>
          )
In the first iteration the set M1 is obtained. M1 consists of two β-element subsets with
the age equals to k-1 (if the distance is less affine α) and the age equals k+1 (if affine
distance greater than or equal to α), where s1≥s due to cloning operation. The
dimension of M1 is finite and equals (due to the finite of S):
M1  p1l1m1 | (k  1) || (k  1) | (5)
where p1 – the probability Pα,
l1 – cloning coefficient in the first step,
m1 – mutation coefficient in the first step,
β(k - 1) – the number of β-elements which have age is equal to k -1,
β(k + 1) – the number of β-elements which have age is equal to k+1.
Iteration 2 is calculated based on the re-use of cloning and mutation operations
taking the results obtained in the previous iteration, that is:
M i  C(M (M i 1)) | P 
C(M (C(M (M i 2 )))) | P  C(M ...( M1)...) | P
Thus, the result of iteration 2 is as follows:
M 2  C(M (M1)) | P 
and a dimension of M2 is finite and equals to:
| M 2 | p2l2m2 | (k  2) || (k ) || (k  1) |
where the parameters are similar like in Iteration 1.
        </p>
        <p>For the r-th iteration, the set of Mr becomes:
M 2  L(M (M r 1)) | P 

br 2 b(r1)1 br1
 i2
i2 1
br1 b(r1)1
 i1 (k  r) 
i1 1</p>
        <p>r1
br 2r b(r1)1  brj</p>
        <p>j1
 i2r
i2r 1
(k  r  1) ...</p>
        <p>(k  r)
On this stage the βm-elements are appeared because there are β-elements which have
age equals n = k+r. The value of this age equals the threshold when   m .
The dimension Mr is finite and equals:
| M r | prlr mr | (k  r) || (k  r  1) |...
| (k  r 1) || (k  r) | prlr mr |  || m |
where |β| – number of all β-elements;
|βm| – number of all βm-elements.</p>
        <p>The relationship between the count of β-elements and βm-elements is a value
(coefficient) depending on cloning coefficient, mutation coefficient and affinity distance
greater than or equal to a predetermined value. Thus, the proposition that for each ε&gt;0
exists [0,1] such that |β| = λ|βm| is proofed.</p>
        <p>Now, we need to establish the relation between the number of simple β- elements and
βm-elements with the memory from the sets it’s created. Another words, there is the
task to determine the dependence of count β-elements and βm-elements for the two
finite sets which have nesting ratio. To do this, let state Proposition 2.</p>
      </sec>
      <sec id="sec-2-4">
        <title>Proposition 2.</title>
        <p>
          For any two finite sets S1 и S2, where S1  S2 , | S1 | | S2 | , |β1| ≤ |β2| and |βm1|≤ |βm
2|.
(
          <xref ref-type="bibr" rid="ref5">6</xref>
          )
(
          <xref ref-type="bibr" rid="ref6">7</xref>
          )
(
          <xref ref-type="bibr" rid="ref7">8</xref>
          )
(
          <xref ref-type="bibr" rid="ref8">9</xref>
          )
(
          <xref ref-type="bibr" rid="ref9">10</xref>
          )
        </p>
      </sec>
      <sec id="sec-2-5">
        <title>Proof</title>
        <p>The proof is reduced to a repetition of the iterations of the Proposition 1, but this time
for two sets S1 and S2 with a comparison of the results.</p>
        <p>Thus, there is a direct dependency between simple β-elements from βm-elements
which allows to estimate the amount of generated β-elements and βm-elements.
Besides, if we have finite sets we can predict the number of β-elements and βm-elements.
It helps us to design the information systems for classifying.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Conclusion References</title>
      <p>Thus, there is a dependency between the simple β-elements from βm-elements within a
finite set of emails or data blocks. It can help to predict the amount of memory
allocated for the creation and storage the β-elements from βm-elements in 2CAIS. The
information systems which can be built using this approach can classify emails or data
blocks on two classes: reliable class and non-reliable class. It can be very necessary
for creating the intrusion detection systems based on its content.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Vasylyev</surname>
            <given-names>VI</given-names>
          </string-name>
          .
          <source>Intelligent Information Security Systems</source>
          . Moscow, Mashinostroenie Publ.,
          <year>2012</year>
          ;
          <fpage>20</fpage>
          -
          <lpage>22</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Vacca</surname>
            <given-names>JR</given-names>
          </string-name>
          .
          <source>Computer and Information Security Handbook. Newnes</source>
          ,
          <year>2012</year>
          ;
          <fpage>330</fpage>
          -
          <lpage>335</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. Nunes L.
          <source>Artificial Immune Systems: A New Computational Intelligence Approach</source>
          . Springer Science &amp; Business Media Publ.,
          <year>2002</year>
          ;
          <fpage>2</fpage>
          -
          <lpage>4</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Haikin</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>Neural networks</article-title>
          . Moscow. Vilyams Publ.,
          <year>2008</year>
          ;
          <fpage>32</fpage>
          -
          <lpage>34</lpage>
          . [in Russian]
          <volume>5</volume>
          .
          <string-name>
            <surname>Abe</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>Support Vector Machines for Pattern Classification</article-title>
          . Springer Science &amp; Business Media Publ.,
          <year>2005</year>
          ;
          <fpage>39</fpage>
          -
          <lpage>40</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kollias</surname>
            <given-names>S</given-names>
          </string-name>
          .
          <source>Artificial Neural Networks</source>
          . Springer Science &amp; Business Media Publ.,
          <year>2006</year>
          ;
          <fpage>161</fpage>
          -
          <lpage>162</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          7.
          <source>Artificial Immune Systems and Their Applications</source>
          , Edited by D. Dasgupta Springer Verlag Publ.,
          <year>1999</year>
          ; 306 p.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          8.
          <string-name>
            <surname>Tarakanov</surname>
            <given-names>AO</given-names>
          </string-name>
          .
          <article-title>Immunocomputing: principles and applications</article-title>
          . Springer Verlag, New York Publ.,
          <year>2003</year>
          ; 193 p.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          9.
          <string-name>
            <surname>Vacca</surname>
            <given-names>JR</given-names>
          </string-name>
          .
          <source>Computer and Information Security Handbook. Newnes</source>
          ,
          <year>2012</year>
          ;
          <fpage>330</fpage>
          -
          <lpage>335</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          10.
          <string-name>
            <surname>Borger</surname>
            <given-names>E.</given-names>
          </string-name>
          <article-title>The Abstract State Machines Method for High-Level System Design and Analysis</article-title>
          .
          <source>Dipartimento di Informatica</source>
          , Universita di Pisa Publ.,
          <year>2007</year>
          ;
          <fpage>30</fpage>
          -
          <lpage>35</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          11.
          <string-name>
            <surname>Shim</surname>
            <given-names>JK</given-names>
          </string-name>
          .
          <article-title>Information Systems and Technology for the Noninformation Systems Executive</article-title>
          . CRC Press Publ.,
          <year>2000</year>
          ;
          <fpage>230</fpage>
          -
          <lpage>235</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          12.
          <string-name>
            <surname>Lunt</surname>
            <given-names>TF.</given-names>
          </string-name>
          <article-title>A real-time intrusion-detection expert system (IDES)</article-title>
          .
          <source>Final Technical Report</source>
          ,
          <year>1992</year>
          ;
          <fpage>10</fpage>
          -
          <lpage>13</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          13.
          <string-name>
            <surname>Burlakov</surname>
            <given-names>ME</given-names>
          </string-name>
          .
          <article-title>The method of filtering incoming traffic on the basis of a two-layer recurrent neural network</article-title>
          .
          <source>Polzunovsky vestnik</source>
          ,
          <year>2012</year>
          ;
          <volume>3</volume>
          (
          <issue>2</issue>
          ):
          <fpage>215</fpage>
          -
          <lpage>219</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          14.
          <string-name>
            <surname>Burlakov</surname>
            <given-names>ME.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Osipov</surname>
            <given-names>МN</given-names>
          </string-name>
          .
          <article-title>Security audit of the local area network using a dynamic system neurons reacting to the sequence</article-title>
          . Information counteraction to threats of terrorism,
          <year>2013</year>
          ;
          <volume>20</volume>
          :
          <fpage>166</fpage>
          -
          <lpage>170</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          15.
          <string-name>
            <surname>Burlakov</surname>
            <given-names>ME</given-names>
          </string-name>
          .
          <article-title>On some optimization models of the artificial neural networks by genetic algorithms</article-title>
          .
          <source>Proceeding of the International Scientific Conference (PIT-2015)</source>
          , Samara: Samara Scientific Center of RAS Publ.,
          <year>2014</year>
          ;
          <fpage>99</fpage>
          -
          <lpage>105</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          16.
          <string-name>
            <surname>Delvin</surname>
            <given-names>D</given-names>
          </string-name>
          ,
          <string-name>
            <surname>O'Sullivan B</surname>
          </string-name>
          .
          <article-title>Satisfiability as a Classification Problem</article-title>
          . University College Cork Publ. URL: http://www.cs.ucc.ie/~osullb/pubs/classification.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          17.
          <string-name>
            <surname>Fernandez-Delgado</surname>
            <given-names>M</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cernadas</surname>
            <given-names>E</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barro</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>Do we Need Hundreds of Classifiers to Solve Real World Classification Problems</article-title>
          . University of Santiago de Compostela Publ. URL: http://jmlr.csail.mit.edu/papers/volume15/delgado14a/delgado14a.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          18.
          <string-name>
            <surname>Schapire</surname>
            <given-names>R.</given-names>
          </string-name>
          <article-title>Machine Learning Algorithms for Classification</article-title>
          . Princeton University Publ. URL: http://www.cs.princeton. edu/~schapire/talks/picasso-minicourse.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          19.
          <string-name>
            <surname>Burlakov</surname>
            <given-names>ME</given-names>
          </string-name>
          .
          <article-title>Two-classification artificial immune system</article-title>
          .
          <source>Vestnik Samara</source>
          State University,
          <year>2014</year>
          ;
          <volume>7</volume>
          (
          <issue>118</issue>
          ):
          <fpage>207</fpage>
          -
          <lpage>221</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>