A Layered Multi-Agent Detection Model for Abnormal Intrusion Based on Danger Theory

A layered multi-agent detection model for abnormal intrusion, based on danger theory, is presented according to the research on the danger theory and artificial immunity. The model, with three layers in the frame, conducts the real time monitoring and danger judgment on the host computer and network resource before it recognizes the nonself, and then the danger signal activates the immunity recognition. The danger judgment conducted by cloud model can recognize the harmful self and harmful nonself effectively, which ensures the system safety and improves the performance of detection system. Thus, the probability of misinformation and omission will decrease to some extent.