Distributed and Scalable Intrusion Detection System Based on Agents and Intelligent Techniques

被引:8
|
作者
El-Semary, Aly M. [1 ]
Mostafa, Mostafa Gadal-Haqq M. [2 ]
机构
[1] Al Azhar Univ, Fac Engn, Dept Syst & Comp Engn, Cairo, Egypt
[2] Ain Shams Univ, Fac Comp & Informat Sci, Dept Comp Sci, Cairo, Egypt
来源
关键词
Data-Mining; Fuzzy Logic; IDS; Intelligent Techniques; Network Security; Software Agents;
D O I
10.3745/JIPS.2010.6.4.481
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet explosion and the increase in crucial web applications such as e-banking and e-commerce, make essential the need for network security tools. One of such tools is an Intrusion detection system which can be classified based on detection approachs as being signature-based or anomaly-based. Even though intrusion detection systems are well defined, their cooperation with each other to detect attacks needs to be addressed. Consequently, a new architecture that allows them to cooperate in detecting attacks is proposed. The architecture uses Software Agents to provide scalability and distributability. It works in two modes: learning and detection. During learning mode, it generates a profile for each individual system using a fuzzy data mining algorithm. During detection mode, each system uses the FuzzyJess to match network traffic against its profile. The architecture was tested against a standard data set produced by MIT's Lincoln Laboratory and the primary results show its efficiency and capability to detect attacks. Finally, two new methods, the memory-window and memoryless-window, were developed for extracting useful parameters from raw packets. The parameters are used as detection metrics.
引用
收藏
页码:481 / 500
页数:20
相关论文
共 50 条
  • [1] Intelligent Agents for Distributed Intrusion Detection System
    Benattou, M.
    Tamine, K.
    PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY, VOL 6, 2005, : 190 - 193
  • [2] A Distributed Intrusion Detection System Based on Agents
    Liu, Jianxiao
    Li, Lijuan
    PACIIA: 2008 PACIFIC-ASIA WORKSHOP ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION, VOLS 1-3, PROCEEDINGS, 2008, : 531 - 535
  • [3] A Distributed Intrusion Detection System Based on Mobile Agents
    Mo Xiu-liang
    Wang Chun-dong
    Wang Huai-bin
    PROCEEDINGS OF THE 2009 2ND INTERNATIONAL CONFERENCE ON BIOMEDICAL ENGINEERING AND INFORMATICS, VOLS 1-4, 2009, : 2110 - 2114
  • [4] INTELLIGENT AGENTS FOR INTRUSION DETECTION IN DISTRIBUTED COMPUTER SYSTEMS
    Walkowiak, Tomasz
    Parazel, Artur
    Mazurkiewicz, Jacek
    MENDELL 2009, 2009, : 322 - 327
  • [5] A model of intelligent agent based distributed intrusion detection system
    Fu, W
    Meng, B
    PROCEEDINGS OF 2003 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE & ENGINEERING, VOLS I AND II, 2003, : 92 - 95
  • [6] Design of a distributed intrusion detection system based on independent agents
    Du, Y
    Wang, HQ
    Pang, YG
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON INTELLIGENT SENSING AND INFORMATION PROCESSING, 2004, : 254 - 257
  • [7] Intelligent agents for intrusion detection
    Helmer, GG
    Wong, JSK
    Honavar, V
    Miller, L
    1998 IEEE INFORMATION TECHNOLOGY CONFERENCE, PROCEEDINGS, 1998, : 121 - 124
  • [8] An Efficient and Scalable Intrusion Detection System on Logs of Distributed Applications
    Lanoe, David
    Hurfin, Michel
    Totel, Eric
    Maziero, Carlos
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2019, 2019, 562 : 49 - 63
  • [9] Distributed Intrusion Detection System using Mobile Agents
    Trivedi, Bhushan
    Rajput, Jayant
    Dwivedi, Chintan
    Jobanputra, Pinky
    COMPUTING, COMMUNICATION, AND CONTROL, 2011, 1 : 57 - 61
  • [10] An Useful Communication Mechanism for Distributed Agents-Based Intrusion Detection System
    DU Ye School of Computer and Information Technology
    Wuhan University Journal of Natural Sciences, 2006, (06) : 1801 - 1804