• DocumentCode
    2827066
  • Title

    A network intrusion detection system with the snooping agents

  • Author

    Zeng, Bin ; Yao, Lu ; Chen, ZhiChen

  • Author_Institution
    Dept. of Manage., Naval Univ. of Eng., Wuhan, China
  • Volume
    3
  • fYear
    2010
  • fDate
    22-24 Oct. 2010
  • Abstract
    In order to increase the protection ability of the network intrusion diction system (NIDS), it is important to gather the host information of the intruder. In the proposed IDS called NIDS-SA, three basic components are developed to support the active monitoring capability, Intrusion Detection Node (IDN), Intrusion Detection Coordinator (IDC), and Snooper Agent (SA). The IDN is used to capture packets, de-multiplex packets, detect local intrusion and infer intrusion. The IDC is installed in an administration workstation for communicating and managing IDNs, it can also do the intrusion detection and intrusion inferring. The RA consists of several snoop functions for information gathering. After an attack behavior is detected, the RA may launch some kinds of information gathering functions to the attacker, so that the proposed NIDS-SA has the active snoop ability. Furthermore, NIDS-SA includes the functions of the pattern matching and statistical inference. To ensure the secure communication ability between IDC and IDNs, the cryptography-based mechanisms are applied in the design phase of the proposed NIDS-SA. An intrusion detection experiment is carried out in our campus to simulate the real attack scenarios and validate the performance of NIDS-SA.
  • Keywords
    computer network security; cryptography; data mining; demultiplexing; inference mechanisms; pattern matching; statistical analysis; NIDS-SA; active monitoring capability; active snoop ability; administration workstation; attack behavior detection; cryptography-based mechanism; information gathering; intrusion detection coordinator; intrusion detection node; intrusion inferring; local intrusion detection; network intrusion detection system; packet demultiplexing; pattern matching; protection ability; secure communication; snoop function; snooper agent; snooping agents; statistical inference; Engines; Fires; IP networks; Multi agent system; Network intrusion detection system; Pattern matching; Statistical analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Application and System Modeling (ICCASM), 2010 International Conference on
  • Conference_Location
    Taiyuan
  • Print_ISBN
    978-1-4244-7235-2
  • Electronic_ISBN
    978-1-4244-7237-6
  • Type

    conf

  • DOI
    10.1109/ICCASM.2010.5620022
  • Filename
    5620022