DocumentCode
2827066
Title
A network intrusion detection system with the snooping agents
Author
Zeng, Bin ; Yao, Lu ; Chen, ZhiChen
Author_Institution
Dept. of Manage., Naval Univ. of Eng., Wuhan, China
Volume
3
fYear
2010
fDate
22-24 Oct. 2010
Abstract
In order to increase the protection ability of the network intrusion diction system (NIDS), it is important to gather the host information of the intruder. In the proposed IDS called NIDS-SA, three basic components are developed to support the active monitoring capability, Intrusion Detection Node (IDN), Intrusion Detection Coordinator (IDC), and Snooper Agent (SA). The IDN is used to capture packets, de-multiplex packets, detect local intrusion and infer intrusion. The IDC is installed in an administration workstation for communicating and managing IDNs, it can also do the intrusion detection and intrusion inferring. The RA consists of several snoop functions for information gathering. After an attack behavior is detected, the RA may launch some kinds of information gathering functions to the attacker, so that the proposed NIDS-SA has the active snoop ability. Furthermore, NIDS-SA includes the functions of the pattern matching and statistical inference. To ensure the secure communication ability between IDC and IDNs, the cryptography-based mechanisms are applied in the design phase of the proposed NIDS-SA. An intrusion detection experiment is carried out in our campus to simulate the real attack scenarios and validate the performance of NIDS-SA.
Keywords
computer network security; cryptography; data mining; demultiplexing; inference mechanisms; pattern matching; statistical analysis; NIDS-SA; active monitoring capability; active snoop ability; administration workstation; attack behavior detection; cryptography-based mechanism; information gathering; intrusion detection coordinator; intrusion detection node; intrusion inferring; local intrusion detection; network intrusion detection system; packet demultiplexing; pattern matching; protection ability; secure communication; snoop function; snooper agent; snooping agents; statistical inference; Engines; Fires; IP networks; Multi agent system; Network intrusion detection system; Pattern matching; Statistical analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Application and System Modeling (ICCASM), 2010 International Conference on
Conference_Location
Taiyuan
Print_ISBN
978-1-4244-7235-2
Electronic_ISBN
978-1-4244-7237-6
Type
conf
DOI
10.1109/ICCASM.2010.5620022
Filename
5620022
Link To Document