DocumentCode :
1778028
Title :
Collective intrusion detection in wide area networks
Author :
Nafir, Abdenacer ; Mazouzi, Smaine ; Chikhi, Salim
Author_Institution :
Dept. d´Inf., Univ. 20 Aout 1955, Skikda, Algeria
fYear :
2014
fDate :
23-25 June 2014
Firstpage :
46
Lastpage :
51
Abstract :
We present in this paper a collective approach for intrusion detection in wide area networks. We use the multi-agent paradigm to model the proposed distributed system. In this system, an agent, which plays several roles, is situated on each node of the net. The first role of an agent is to perform the work of a local intrusion detection system (IDS). Periodically, it proceeds to exchange security data within its local neighbouring. The agent neighbouring consists of IDS agents of local neighbour nodes. The goal of such an approach is to consolidate the decision, regarding every suspected security event. Unlike previous works having proposed distributed systems for intrusion detection, our system is not restricted to data sharing. It proceeds in the case of a conflict to a negotiation between neighbouring agents in order to produce a consensual decision. So, the proposed system is fully distributed. It does not require any central or hierarchical control, which compromises its scalability, specially in wide area networks such as Internet. Indeed, in this kind of networks, some attacks like distributed denial of service (DDoS) require fully distributed defence. Experiments on our system show its potential for satisfactory DDoS attack detection.
Keywords :
Internet; computer network security; multi-agent systems; wide area networks; IDS; Internet; agent neighbouring; collective intrusion detection; data sharing; distributed denial of service; distributed system; local neighbour nodes; multiagent paradigm; satisfactory DDoS attack detection; security data; security event; wide area networks; Computer crime; Computer hacking; Internet; Intrusion detection; Multi-agent systems; Wide area networks; DDoS; IDS; Intrusion detection; Multi-agent systems; Network security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovations in Intelligent Systems and Applications (INISTA) Proceedings, 2014 IEEE International Symposium on
Conference_Location :
Alberobello
Print_ISBN :
978-1-4799-3019-7
Type :
conf
DOI :
10.1109/INISTA.2014.6873596
Filename :
6873596
Link To Document :
بازگشت