|
ABSTRACT
This paper proposes a distributed intrusion detection system based on autonomous and mobile agents. The proposed system has four types of agents: connection agents, analyser agents, an administrator agent and a crisis agent. The system makes use of a Sniffer module to capture packets circulated on the network. A pattern matching approach is applied by the analyzer agents to scan the captured packets and detect eventual attacks. A prototype has been designed and implemented.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
M. Aashish 2004. Agents for Intrusion Detection. Web Site: www.cse.buffalo.edu/~sbraynov/seminar%202004/presenttations/Aashish.ppt.
|
| |
2
|
J. S. Balasubramaniyan,. J. O. Garcia-Fernandez, D. Isacoff, E. Spafford, and. Zamboni D, June 1998. An architecture for intrusion detection using autonomous agents. Technical Report 98/05, COAST Laboratory - Purdue University.
|
| |
3
|
B. Bauer, H. Van Dyke Parunak, James Odell, (2001), "Extending UML for Agents" http://www.erim.org/~vparunak/.
|
| |
4
|
|
| |
5
|
|
| |
6
|
D. Boughaci and H. Drias, (2005), "Taboo Search as an Intelligent Agent for Bid Evaluation", in International journal of Internet and Enterprise Management, Inderscience Publisher, Vol 3, issue 2, pp 170--186.
|
| |
7
|
|
| |
8
|
H. Debar, M. Dacier, and A. Wespi, June 1998. Towards a taxonomy of intrusion-detection systems. Internal RZ 3030, IBM Zurich Research Laboratory, Saumerstrasse 4, CH-8803 Ruschlikon, Switzerland.
|
| |
9
|
Stan Franklin , Art Graesser, Is it an Agent, or Just a Program?: A Taxonomy for Autonomous Agents, Proceedings of the Workshop on Intelligent Agents III, Agent Theories, Architectures, and Languages, p.21-35, August 12-13, 1996
|
| |
10
|
|
 |
11
|
|
| |
12
|
Guy Helmer , Johnny Wong , Mark Slagell , Vasant Honavar , Les Miller , Yanxin Wang , Xia Wang , Natalia Stakhanova, Software fault tree and coloured Petri net based specification, design and implementation of agent-based intrusion detection systems, International Journal of Information and Computer Security, v.1 n.1/2, p.109-142, January 2007
[doi> 10.1504/IJICS.2007.012246]
|
| |
13
|
|
| |
14
|
Judith Hochberg , Kathleen Jackson , Cathy Stallings , J. F. McClary , David DuBois , Josephine Ford, NADIR: an automated system for detecting network intrusion and misuse, Computers and Security, v.12 n.3, p.235-248, May 1993
[doi> 10.1016/0167-4048(93)90110-Q]
|
| |
15
|
H. S. Javitz, A. Valdes, TF. Lunt, A. Tamaru. M. Tyson., and J. Lowrance., 1993. Next generation intrusion detection expert system (NIDES). Technical Report A016-Rationales, SRI.
|
| |
16
|
P. Noriega, and C. Sierra. (eds.).(1999) "Agent-Mediated Electronic Commerce", LNAI 1571, Springer, 1999.
|
| |
17
|
S. Kumar and E. H. Spafford, 1994. A pattern-matching model for misuse intrusion detection. In Proceedings of the national computer security conference, pp 11--21.
|
| |
18
|
TF. Lunt and R. Jagannathan, 1988. A prototype real-time intrusion-detection expert system. In Proceedings of the IEEE Symposium on Security and Privacy, pp 59--66.
|
| |
19
|
L. Mé. Gassata, 1998. A genetic algorithm as an alternative tool for security audit trails analysis. In First international workshop on the Recent Advances in Intrusion Detection http://www.zurich.ibm.com/~dac/Prog_RAID98/Table_of_content.html.
|
| |
20
|
L. Mé and V. Alanou, 1996. Détection d'intrusion dans un système informatique: méthodes et outils. TSI, Revue des sciences et technologies de l'information 15(4):429--450.
|
| |
21
|
Phillip A. Porras and Peter G. Neumann. EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances. In the National Information Systems Security Conference, October 1997.
|
| |
22
|
Vaccaro H. S and Liepins G. E, May 1989. Detection of anomalous computer session activity". In Proceedings of the IEEE Symposium on Security and Privacy.
|
| |
23
|
Y. Wang, S. Behera, J. Wong, G. Helmer, V. Honavar, L. Miller and R. Lutz. (2006) Towards Automatic Generation of Mobiles Agents for Distributed Intrusion Detection Systems. Journal of Systems and Software. Vol. 79. pp. 1--14, 2006.
|
| |
24
|
M. Wooldridge. N. R. Jennings, (1995), "Intelligent Agents: theory and practice", Knowledge engineering Review, pp 115--152.
|
| |
25
|
|
| |
26
|
Q. Zhang and R. Janakiraman, "Indra: A Distributed Approach to Network Intrusion Detection and Prevention", Washington University Technical Report # WUCS-01-30, 2001.
|
| |
27
|
Aglets Web: http://www.trl.ibm.com/aglets/
|
| |
28
|
Java Web site http://java.sun.com/
|
|