DocumentCode :
454282
Title :
A distributed agent-based approach to intrusion detection using the lightweight PCC anomaly detection classifier
Author :
Xie, Zongxing ; Quirino, Thiago ; Shyu, Mei-Ling ; Chen, Shu-Ching ; Chang, LiWu
Author_Institution :
Dept. of Electr. & Comput. Eng., Miami Univ., Coral Gables, FL
Volume :
1
fYear :
2006
fDate :
5-7 June 2006
Abstract :
In this paper, a novel agent-based distributed intrusion detection system (IDS) is proposed, which integrates the desirable features provided by the distributed agent-based design methodology with the high accuracy and speed response of the principal component classifier (PCC). Experimental results have shown that the PCC lightweight anomaly detection classifier outperforms other existing anomaly detection algorithms such as the KNN and LOF classifiers. In order to assess the performance of the PCC classifier on a real network environment, the relative assumption model together with feature extraction techniques are used to generate normal and anomalous traffic in a LAN testbed. Finally, scalability and response performance of the proposed system are investigated through the simulation of the proposed communication architecture. The simulation results demonstrate a satisfactory linear relationship between the degradation of response performance and the scalability of the system
Keywords :
feature extraction; local area networks; pattern classification; principal component analysis; real-time systems; security of data; software agents; telecommunication security; telecommunication traffic; IDS; LAN testbed; PCC; anomaly detection algorithm; communication architecture; distributed agent-based approach; feature extraction technique; intrusion detection system; local area network; network traffic; principal component classifier; real network environment; scalability; Degradation; Design methodology; Detection algorithms; Feature extraction; Intrusion detection; Local area networks; Scalability; Telecommunication traffic; Testing; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Sensor Networks, Ubiquitous, and Trustworthy Computing, 2006. IEEE International Conference on
Conference_Location :
Taichung
Print_ISBN :
0-7695-2553-9
Type :
conf
DOI :
10.1109/SUTC.2006.1636211
Filename :
1636211
Link To Document :
بازگشت