DocumentCode :
1966279
Title :
A cooperative intrusion detection system based on autonomous agents
Author :
Yongle, Dong ; Jun, Qian ; Meilin, Shi
Author_Institution :
Tsinghua Univ., Beijing, China
Volume :
2
fYear :
2003
fDate :
4-7 May 2003
Firstpage :
861
Abstract :
Widespread attacks involving multiple hosts/networks happen more frequently as internetworking among computer systems via the Internet becomes more widely and keeps rapid increase. Due to lack of information, it can be quite difficult for conventional intrusion detection systems to identify such attacks in progress. Cooperative intrusion detection, on the basis of information sharing, is proved as a necessary measure to detect widespread attacks by other researcher D. Frincke (2000), Polla, D. et al., (1998). This paper presents a cooperative approach for intrusion detection that provides a method for individual ID components working cooperatively to perform concerted detections. Being constructed on the basis of ID components, CoIDS can adopt both existed (usually more mature) and new ID techniques. This makes CoIDS extensible and scalable. In addition, an ID component is essentially an autonomous agent, which makes CoIDS available with certain loss of functionality even when the intrusion detection manager does not work. Its reliability is also improved because failure of one ID component will not cause any other to stop working. Furthermore, it improved the accuracy of detection for conventional intrusions by validating analysis result with data from different ID components.
Keywords :
Internet; cooperative systems; internetworking; safety systems; Internet; autonomous agent; computer system; concerted detection; cooperative intrusion detection system; individual ID component; information sharing; internetworking; multiple host; multiple network; widespread attack detection; Autonomous agents; Computer networks; Computer viruses; Data analysis; Decision making; Internetworking; Intrusion detection; Proposals; Prototypes; Wide area networks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Electrical and Computer Engineering, 2003. IEEE CCECE 2003. Canadian Conference on
ISSN :
0840-7789
Print_ISBN :
0-7803-7781-8
Type :
conf
DOI :
10.1109/CCECE.2003.1226031
Filename :
1226031
Link To Document :
بازگشت