Title :
A network intrusion detection system with the snooping agents
Author :
Zeng, Bin ; Yao, Lu ; Chen, ZhiChen
Author_Institution :
Dept. of Manage., Naval Univ. of Eng., Wuhan, China
Abstract :
In order to increase the protection ability of the network intrusion diction system (NIDS), it is important to gather the host information of the intruder. In the proposed IDS called NIDS-SA, three basic components are developed to support the active monitoring capability, Intrusion Detection Node (IDN), Intrusion Detection Coordinator (IDC), and Snooper Agent (SA). The IDN is used to capture packets, de-multiplex packets, detect local intrusion and infer intrusion. The IDC is installed in an administration workstation for communicating and managing IDNs, it can also do the intrusion detection and intrusion inferring. The RA consists of several snoop functions for information gathering. After an attack behavior is detected, the RA may launch some kinds of information gathering functions to the attacker, so that the proposed NIDS-SA has the active snoop ability. Furthermore, NIDS-SA includes the functions of the pattern matching and statistical inference. To ensure the secure communication ability between IDC and IDNs, the cryptography-based mechanisms are applied in the design phase of the proposed NIDS-SA. An intrusion detection experiment is carried out in our campus to simulate the real attack scenarios and validate the performance of NIDS-SA.
Keywords :
computer network security; cryptography; data mining; demultiplexing; inference mechanisms; pattern matching; statistical analysis; NIDS-SA; active monitoring capability; active snoop ability; administration workstation; attack behavior detection; cryptography-based mechanism; information gathering; intrusion detection coordinator; intrusion detection node; intrusion inferring; local intrusion detection; network intrusion detection system; packet demultiplexing; pattern matching; protection ability; secure communication; snoop function; snooper agent; snooping agents; statistical inference; Engines; Fires; IP networks; Multi agent system; Network intrusion detection system; Pattern matching; Statistical analysis;
Conference_Titel :
Computer Application and System Modeling (ICCASM), 2010 International Conference on
Conference_Location :
Taiyuan
Print_ISBN :
978-1-4244-7235-2
Electronic_ISBN :
978-1-4244-7237-6
DOI :
10.1109/ICCASM.2010.5620022