• DocumentCode
    3626794
  • Title

    Agent-Based Network Intrusion Detection System

  • Author

    Vojtech Krmicek;Pavel Celeda;Martin Rehak;Michal Pechoucek

  • Author_Institution
    Masaryk Univ., Brno
  • fYear
    2007
  • Firstpage
    528
  • Lastpage
    531
  • Abstract
    The paper presents security platform based on agents as an efficient and robust solution for high-performance intrusion detection system designed for deployment on high-speed network links. The proposed detection algorithm is based on extension of trust modeling techniques with representation of uncertain identities, context representation and implicit assumption that significant traffic anomalies are a result of potentially malicious action. The heterogeneous anomaly detection methods are used by cooperating agents and then correlated using a reputation mechanism. To satisfy the performance requirements, wire-speed data acquisition layer is based on hardware-accelerated Net- Flow probes that provide overview of current network traffic. The output of multi-agent detection layer is presented to operator by a dedicated analyst interface agent, which retrieves additional information to facilitate incident analysis. Our performance results illustrate the potential of combination of high-speed hardware with agents-based detection and advanced analyst interface.
  • Keywords
    "Intrusion detection","Telecommunication traffic","Information analysis","Robustness","High-speed networks","Detection algorithms","Context modeling","Traffic control","Data acquisition","Probes"
  • Publisher
    ieee
  • Conference_Titel
    Intelligent Agent Technology, 2007. IAT ´07. IEEE/WIC/ACM International Conference on
  • Print_ISBN
    0-7695-3027-3;978-0-7695-3027-7
  • Type

    conf

  • DOI
    10.1109/IAT.2007.111
  • Filename
    4407339