DIDMA: A distributed intrusion detection system using mobile agents

被引:30
|
作者
Kannadiga, P [1 ]
Zulkernine, M [1 ]
机构
[1] Queens Univ, Sch Comp, Kingston, ON K7L 3N6, Canada
关键词
D O I
10.1109/SNPD-SAWN.2005.31
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The widespread proliferation of Internet connections has made current computer networks more vulnerable to intrusions than before. In network intrusions' there may be multiple computing nodes that are attacked by intruders. The evidences of intrusions have to be gathered from all such attacked nodes. An intruder may move between multiple nodes in the network to conceal the origin of attack., or misuse some compromised hosts to launch the attack on other nodes. To detect such intrusion activities spread over the whole network, we present a new intrusion detection system (IDS) called Distributed Intrusion Detection using Mobile Agents (DIDAM). DIDAM uses a set of software entities called mobile agents that can move from one node to another node within a network, and perform the task of aggregation and correlation of the intrusion related data that it receives from another set of software entities called the static agents. Mobile agents reduce network bandwidth usage by moving data analysis computation to the location of the intrusion data, support heterogeneous plat-forms, and offer a lot of flexibility in creating a distributed IDS. DIDAM utilizes the above-mentioned beneficial features offered by mobile agent technology and addresses some of the issues with centralized IDS models. The detailed architecture and implementation of a prototype of DIDMA are described It has been tested using some well-known attacks and performances have been com-pared with centralized IDS models.
引用
收藏
页码:238 / 245
页数:8
相关论文
共 50 条
  • [31] Research on distributed intrusion detection system based on mobile agent
    Cao, Jin-Gang
    Zheng, Gu-Ping
    PROCEEDINGS OF 2008 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2008, : 1394 - 1399
  • [32] MA_IDS : Mobile Agents for Intrusion Detection System
    Barika, F. A.
    El Kadhi, N.
    Ghedira, K.
    2009 IEEE INTERNATIONAL ADVANCE COMPUTING CONFERENCE, VOLS 1-3, 2009, : 900 - +
  • [33] Survival architecture for distributed intrusion detection system (dIDS) using mobile agent.
    Vongpradhip, Sartid
    Sixth IEEE International Symposium on Network Computing and Applications, Proceedings, 2007, : 332 - 338
  • [34] Information-gathering with mobile agents for intrusion detection system
    Asaka, M
    Goto, S
    KNOWLEDGE-BASED SOFTWARE ENGINEERING, 1998, 48 : 23 - 31
  • [35] A novel peer-to-peer intrusion detection system using mobile agents in MANETs
    Xiao, K
    Zheng, J
    Wang, X
    Xue, XY
    PDCAT 2005: SIXTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2005, : 441 - 445
  • [36] Mutual tests using immunity-based diagnostic mobile agents in distributed intrusion detection systems
    Yuji Watanabe
    Yoshiteru Ishida
    Artificial Life and Robotics, 2004, 8 (2) : 163 - 167
  • [37] An architectural framework for distributed intrusion detection using smart agents
    Chatzigiannakis, V
    Androulidakis, G
    Grammatikou, M
    Maglaris, B
    SAM '04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, 2004, : 193 - 199
  • [38] Mobile agents for computer intrusion detection
    Foo, Simon Y.
    Arradondo, Michael
    Proc Annu Southeast Symp Syst Theory, 1600, (517-521):
  • [39] Mobile agents for computer intrusion detection
    Foo, SY
    Arradondo, M
    PROCEEDINGS OF THE THIRTY-SIXTH SOUTHEASTERN SYMPOSIUM ON SYSTEM THEORY, 2004, : 517 - 521
  • [40] Distributed and Scalable Intrusion Detection System Based on Agents and Intelligent Techniques
    El-Semary, Aly M.
    Mostafa, Mostafa Gadal-Haqq M.
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2010, 6 (04): : 481 - 500