• DocumentCode
    3021838
  • Title

    A Hybrid Artificial Immune and Mobile Agent Intrusion Detection Based Model for Computer Network Operations

  • Author

    Machado, R.B. ; Boukerche, A. ; Sobral, J.B. ; Jucá, K. R L ; Notare, M. S M A

  • Author_Institution
    Comput. Sci. Program, Santa Clara Univ., CA, USA
  • fYear
    2005
  • fDate
    04-08 April 2005
  • Abstract
    Agent Based Models are the natural extension of the Ising or Cellular Automata-like models which have been used in the past decades to simulate various physical phenomena. By taking advantages of the main features of such models, coupled with nature based models such as artificial immune systems we present a novel artificial immune and agent based intrusion detection model for large computer networks. Our solution is based upon several security levels, event based model, and a simple computational abstraction where an anomaly detection technique is designed to monitor the users´ registrations to the operational targeted system, e.g., UNIX-like implementation. In our model, the events´ generation model is processed using the Unix Syslog-ng tool, the events´ analysis using the Logcheck tool, while the activities of the users and the execution of the both reactive and pro-active events´ activities are implemented within an artificial immune and mobile agent based infrastructure. We have implemented and designed our model to differentiate among attacks, security violations, and several other security levels. In this paper we present our model, and show how mobile agent and artificial immune paradigms can be used to design efficient intrusion detection systems. we also discuss the validation of our model followed by a set of experiments we have carried out to evaluate the performance of our model using realistic case studies.
  • Keywords
    Unix; computer network management; mobile agents; security of data; Logcheck tool; Unix Syslog-ng tool; agent based model; anomaly detection; computer network security; event generation; hybrid artificial immune system; intrusion detection system; mobile agent; Artificial immune systems; Complex networks; Computational modeling; Computer networks; Computerized monitoring; Immune system; Intrusion detection; Mobile agents; Organisms; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Processing Symposium, 2005. Proceedings. 19th IEEE International
  • Print_ISBN
    0-7695-2312-9
  • Type

    conf

  • DOI
    10.1109/IPDPS.2005.33
  • Filename
    1420080