• DocumentCode
    1608305
  • Title

    An architecture of a distributed intrusion detection system using cooperating agents

  • Author

    Sen, Jaydip ; Sengupta, Indranil ; Chowdhury, Piyali Roy

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Indian Inst. of Technol., Kharagpur, India
  • fYear
    2006
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    An intrusion detection system (IDS) is a security mechanism that is expected to monitor and detect intrusions into the computer systems in real time. The currently available intrusion detection systems have a number of problems that limit their configurability, scalability, and efficiency. There have been some propositions about distributed architectures based on multiple independent agents working collectively for intrusion detection. However, these distributed intrusion detection systems are not fully distributed as most of them centrally analyze data collected from distributed nodes resulting in a single point of failure. In this paper, we propose a distributed architecture with autonomous and cooperating agents without any central analysis component. The agents cooperate by using a hierarchical communication of interests and data, and the analysis of intrusion data is made by the agents at the lowest level of the hierarchy. This architecture provides significant advantages in design of an IDS in terms of scalability, flexibility, extensibility, fault tolerance, and resistance to compromise. We have developed a proof-of-concept prototype, and conducted experiments on the system. The results show the effectiveness of our system in detecting intrusive activities in any network of workstations.
  • Keywords
    multi-agent systems; security of data; computer systems; cooperating agents; distributed architectures; distributed intrusion detection system; distributed nodes; fault tolerance; security mechanism; Computer architecture; Computer security; Computerized monitoring; Data analysis; Failure analysis; Fault tolerance; Independent component analysis; Intrusion detection; Real time systems; Scalability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing & Informatics, 2006. ICOCI '06. International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4244-0219-9
  • Electronic_ISBN
    978-1-4244-0220-5
  • Type

    conf

  • DOI
    10.1109/ICOCI.2006.5276474
  • Filename
    5276474