DocumentCode :
3626793
Title :
High-Speed Network Traffic Acquisition for Agent Systems
Author :
Pavel Celeda;Vojtech Krmicek;Martin Rehak;David Medvigy
Author_Institution :
Masaryk Univ., Brno
fYear :
2007
Firstpage :
477
Lastpage :
480
Abstract :
This paper presents a design of high-speed network traffic acquisition subsystem suitable for agent-based intrusion detection systems. To match the performance requirements and to improve network traffic measurement, wire-speed data acquisition layer is based on hardware-accelerated probes, which provide real-time network traffic statistics. The network traffic is stored in collector servers and pre-processed data is then sent to detection agents that use heterogeneous anomaly detection methods. These methods are correlated by means of trust and reputation models, and the conclusions regarding the maliciousness of the traffic is presented to the operator. Presented system is designed to improve the performance of agent-based intrusion detection systems and allow them to efficiently identify malicious traffic. The main contribution of presented system is its ability to aggregate real-time network-wide statistics from geographically dispersed probes. Traffic acquisition system is designed for deployment on high-speed backbone networks.
Keywords :
"High-speed networks","Telecommunication traffic","Traffic control","Intrusion detection","Probes","Statistics","Data acquisition","Network servers","Aggregates","Real time systems"
Publisher :
ieee
Conference_Titel :
Intelligent Agent Technology, 2007. IAT ´07. IEEE/WIC/ACM International Conference on
Print_ISBN :
0-7695-3027-3;978-0-7695-3027-7
Type :
conf
DOI :
10.1109/IAT.2007.66
Filename :
4407330
Link To Document :
بازگشت