An agent-based hybrid intrusion detection system
2011
Paulins, N., Latvia Univ. of Agriculture, Jelgava (Latvia)
Intrusion Detection Systems is defined as a component that analyses system and user operations in computer and network system to protect it from possible intrusions. Current intrusion detection technologies have several shortcomings. Applying mobile agents to intrusion detection design is step forward on better intrusion detection. Mobile-agent based distributed intrusion detection systems are very promising for the following reasons: reduction of data movement, load-balance, flexibility, fault-tolerance, detection of distributed attacks. Hybrid intrusion detection is defined by both the method used to detect attacks and the placement of the system on the network. Intrusion detection system may perform either misuse detection or anomaly detection and may be deployed as network-based or host-based system. This paper proposes to distribute classical intrusion detection model with mobile agents making an agent-based hybrid intrusion detection system. The proposed model can help detect simple intrusions in early stage and also distributed intrusions by monitoring several subjects installed on network. Main benefit from mobile agents in such system is ability to generate separate services for specific tasks and analyze unknown user patterns with several methods of artificial intelligence.
Afficher plus [+] Moins [-]Mots clés AGROVOC
Informations bibliographiques
Cette notice bibliographique a été fournie par Fundamental Library of Latvia University of Life Sciences and Technologies
Découvrez la collection de ce fournisseur de données dans AGRIS