The goal of the project is the study of the use of network behavior analysis (NBA) methods together with the host-based artificial immune system techniques that allow analyzing the behavior of unknown code and classifying it as benign or malign, using the honeypot-based approaches. Our proposal links together two advanced intrusion detection concepts that work on the opposite levels of the scale: network behavior analysis uses the statistical data regarding the structure of network traffic, while the honeypot-based application code analysis executes the suspicious code on the target platform and verifies whether it complies with expected classes of legitimate behavior, learned from the observation of legitimate processes on target platform. (en)
Cílem projektu je výzkum metod pro autonomní spolupráci heterogenních detekčních postupů při detekci a analýze škodlivého kódu. Zaměříme se zejména na použití postupů z UI, rozpoznávání a teorie her pro zlepšení kolektivní detekce intruzí. (cs)