Intelligent Multi-agent System for Intrusion Detection and Countermeasures
Author | : Guy Gary Helmer |
Publisher | : |
Total Pages | : 310 |
Release | : 2000 |
ISBN-13 | : 0599971975 |
ISBN-10 | : 9780599971974 |
Rating | : 4/5 (74 Downloads) |
Download or read book Intelligent Multi-agent System for Intrusion Detection and Countermeasures written by Guy Gary Helmer and published by . This book was released on 2000 with total page 310 pages. Available in PDF, EPUB and Kindle. Book excerpt: Intelligent mobile agent systems offer a new approach to implementing intrusion detection systems (IDS). The prototype intrusion detection system, MAIDS, demonstrates the benefits of an agent-based IDS, including distributing the computational effort, reducing the amount of information sent over the network, platform independence, asynchronous operation, and modularity offering ease of updates. Anomaly detection agents use machine learning techniques to detect intrusions; one such agent processes streams of system calls from privileged processes. Misuse detection agents match known problems and correlate events to detect intrusions. Agents report intrusions to other agents and to the system administrator through the graphical user interface (GUI). A sound basis has been created for the intrusion detection system. Intrusions have been modeled using the Software Fault Tree Analysis (SFTA) technique; when augmented with constraint nodes describing trust, contextual, and temporal relationships, the SFTA forms a basis for stating the requirements of the intrusion detection system. Colored Petri Nets (CPN) have been created to model the design of the Intrusion Detection System. Algorithmic transformations are used to create CPN templates from augmented SFT and to create implementation templates from CPNs. The implementation maintains the CPN semantics in the distributed agent-based intrusion detection system.