• DocumentCode
    2178380
  • Title

    A Hybrid Approach to Intrusion Detection and Prevention for Business Intelligence Applications

  • Author

    Yee, Chan Gaik ; Rao, G. S V Radha Krishna

  • Author_Institution
    Fac. of Inf. Technol., Multimedia Univ.
  • fYear
    2006
  • fDate
    Oct. 18 2006-Sept. 20 2006
  • Firstpage
    847
  • Lastpage
    850
  • Abstract
    In this paper, an application-based intrusion detection and prevention (ID/IP) system coupled with data mining and mobile agent technologies is introduced. Under this approach, the ID/IP system consists of a core engine with data sensor, detector, configuration device and alert and response device as its main components. The data sensors posting as designated agents are to gather information from their respective sources in real time. The information gathered by the respective agent is fed into the detector where correlation methods and data mining techniques are employed to analyze and identify any intrusive activity or event. Since information is gathered from various sources by the respective agent, different type of profiles representing normal behavior such as network traffic, users, systems, applications, transactions, alarms and alerts can be built, and deviation from these profiles are considered to be intrusion. A rating model is then used to evaluate the intrusive activities. When an intrusion or attack is detected by the detector and evaluated to have a rating below the threshold value, the configuration device changes the status of the ID/IP system to alert mode and signal the alert and response device to take the necessary actions. Subsequently, mobile response agents are used to carry out response mechanisms at the target and the source
  • Keywords
    competitive intelligence; data mining; mobile agents; security of data; alert device; application-based intrusion detection; business intelligence applications; configuration device; correlation methods; data mining; data sensor; mobile agent technologies; prevention system; response device; Correlation; Data mining; Detectors; Engines; Event detection; Information analysis; Intelligent sensors; Intrusion detection; Mobile agents; Sensor systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Information Technologies, 2006. ISCIT '06. International Symposium on
  • Conference_Location
    Bangkok
  • Print_ISBN
    0-7803-9741-X
  • Electronic_ISBN
    0-7803-9741-X
  • Type

    conf

  • DOI
    10.1109/ISCIT.2006.339856
  • Filename
    4141335