IDSUDA: An Intrusion Detection System Using Distributed Agents
نویسندگان
چکیده
Intrusion-detection systems (IDSs) aim at detecting attacks against information systems. Most intrusiondetection systems currently rely on some type of centralized processing to analyze the data necessary to detect an intruder in real time. A centralized approach can be vulnerable to attack (e.g., Denial of Service). Additionally many of these systems depends on analyzing the log files and packet traces, which is potentially modified by the intruder before the IDS can obtain it, making it's possible for the intruder to hide his activities. Another problem, is that majority of IDSs detect attacks that have known signatures, which is not enough because of the nature of the always and ongoing changes in the methods of intruders to break-in systems. In this paper, a framework called Intrusion Detection System Using Distributed Agents (IDSUDA) was built avoiding the above-mentioned problems and adopting a different architecture. In this framework the software agent technology was employed to extend the capabilities of the classical IDSs. IDSUDA focuses on the attack behavior through monitoring the usage of system different resources to detect deviation from normal usage. So it detects many attacks; the known signatures attacks and also the new ones.
منابع مشابه
Proposing A Distributed Model For Intrusion Detection In Mobile Ad-Hoc Network Using Neural Fuzzy Interface
Security term in mobile ad hoc networks has several aspects because of the special specification of these networks. In this paper a distributed architecture was proposed in which each node performed intrusion detection based on its own and its neighbors’ data. Fuzzy-neural interface was used that is the composition of learning ability of neural network and fuzzy Ratiocination of fuzzy system as...
متن کاملProposing A Distributed Model For Intrusion Detection In Mobile Ad-Hoc Network Using Neural Fuzzy Interface
Security term in mobile ad hoc networks has several aspects because of the special specification of these networks. In this paper a distributed architecture was proposed in which each node performed intrusion detection based on its own and its neighbors’ data. Fuzzy-neural interface was used that is the composition of learning ability of neural network and fuzzy Ratiocination of fuzzy system as...
متن کاملDistributed Intrusion Detection System Using Mobile Agent
The goal of Distributed Intrusion Detection System is to analyze events on the network and identify attacks. The increasing number of network security related incidents makes it necessary for organizations to actively protect their sensitive data with the installation of intrusion detection systems (IDS). There is a difficulty to find intrusion in an distributed network segment from inside as w...
متن کاملDistributed Intrusion Detection using Mobile Agents
DIDMA (Distributed Intrusion Detection using Mobile Agents) is a novel architecture in the field of IDS (Intrusion Detection Systems), utilizing an agent-based approach in order to realize a distributed framework. The novelty in this architecture is the employment of mobile agents as its auditing components. This novel approach overcomes certain problems associated with traditional designs in I...
متن کاملA Framework for Distributed Intrusion Detection using Interest-Driven Cooperating Agents
Current distributed intrusion detection systems are not completely distributed with respect to data analysis because of the presence of centralized data analysis components. This deficiency has many undesirable implications. Here we present a framework for doing distributed intrusion detection with no centralized analysis components. Our approach uses agents that are the only data analysis comp...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006