A misuse detection agent for intrusion detection in a multi-agent architecture

被引:0
|
作者
Mosqueira-Rey, Eduardo [1 ]
Alonso-Betanzos, Amparo [1 ]
Baldonedo del Rio, Belen [1 ]
Lago Pineiro, Jesus [1 ]
机构
[1] Univ A Coruna, La Coruna 15071, Spain
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We describe the design of a misuse detection agent, one of the different agents in a multiagent-based intrusion detection system. This system is being implemented in JADE, a well-known multiagent platform based in Java. The agent analyzes the packets in the network connections using a packet sniffer and then creates a data model based on the information obtained. This data model is the input to a rule-based agent inference engine, which uses the Rete algorithm for pattern matching, and the rules of the signature-based intrusion detection system Snort. Specifically, an implementation in Java language - the Drools-JBoss Rules- was used, and a parser was implemented that converts Snort rules to Drools rules. The use of object-oriented techniques, together with design patterns, means that the agent is flexible, easily configurable and extensible.
引用
收藏
页码:466 / +
页数:3
相关论文
共 50 条
  • [1] Multi-agent based intrusion detection architecture
    Zhang, R
    Qian, DP
    Bao, CM
    Wu, WG
    Guo, XB
    [J]. 2001 INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND MOBILE COMPUTING, PROCEEDINGS, 2001, : 494 - 501
  • [2] A Log Analyzer Agent for Intrusion Detection in a Multi-Agent System
    Porto-Diaz, Iago
    Fontenla-Romero, Oscar
    Alonso-Betanzos, Amparo
    [J]. KNOWLEDGE-BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT I, 2010, 6276 : 168 - 177
  • [3] Multi-agent reinforcement learning for intrusion detection
    Servin, Arturo
    Kudenko, Daniel
    [J]. ADAPTIVE AGENTS AND MULTI-AGENT SYSTEMS, 2008, 4865 : 211 - 223
  • [4] A Multi-Agent Adaptive Architecture for Smart-Grid-Intrusion Detection and Prevention
    Kisielewicz, Tomasz
    Stanek, Stanislaw
    Zytniewski, Mariusz
    [J]. ENERGIES, 2022, 15 (13)
  • [5] A Multi-agent Approach for Intrusion Detection in Distributed Systems
    Forestiero, Agostino
    [J]. MULTIMEDIA COMMUNICATIONS, SERVICES AND SECURITY, MCSS 2015, 2015, 566 : 72 - 82
  • [6] A Multi-agent System for Smartphone Intrusion Detection Framework
    Alzahrani, Abdullah J.
    Ghorbani, Ali A.
    [J]. PROCEEDINGS OF THE 18TH ASIA PACIFIC SYMPOSIUM ON INTELLIGENT AND EVOLUTIONARY SYSTEMS, VOL 1, 2015, : 101 - 113
  • [7] Immunity diversity based multi-agent intrusion detection
    Gu, Yu
    Zhao, Jiashu
    [J]. 2007 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1-10, PROCEEDINGS, 2007, : 3404 - 3409
  • [8] An Immune Multi-agent System for Network Intrusion Detection
    Wang, Dian Gang
    Li, Tao
    Liu, Sun Jun
    Liang, Gang
    Zhao, Kui
    [J]. ADVANCES IN COMPUTATION AND INTELLIGENCE, PROCEEDINGS, 2008, 5370 : 436 - 445
  • [9] Multi-agent based hybrid Intrusion detection system
    Zhang, Bao-Jun
    Pan, Xue-Zeng
    Wang, Jie-Bing
    Ping, Ling-Di
    [J]. Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2009, 43 (06): : 987 - 993
  • [10] Multi-agent peer-to-peer intrusion detection
    Gorodetsky, Vladimir
    Karsaev, Oleg
    Samoylov, Vladimir
    Serebryakov, Sergey
    [J]. COMPUTER NETWORK SECURITY, PROCEEDINGS, 2007, 1 : 260 - +