阐述了危险模式的概况及运行机制,提出了一种基于危险模式的异常检测模型以及相关的算法。该模型通过分析实时系统调用序列中的危险信号,进而判断是否为入侵事件。实验结果表明,该方法具有较高的有效性和检测率。 关键词:危险模式;免疫系统;异常检测 Abstract: The general situation and running mechanism of danger theory are presented in this paper.After that we present an anomaly detection model based on danger theory,describe an interrelated algorithm.The method detects abnormal behavior through analyzing danger signal in the system calls sequences. Experiments show that the method is feasible and effective. Key words: Danger model;Immune system;Anomaly detection