【24h】

The DEMIAN system approach to intrusion detection

机译:舞蹈系统入侵检测方法

获取原文

摘要

This paper presents a small multi-agent system for intrusion detection, the DEMIAN system, which contributes with a new knowledge specification approach to model the behaviour and the communication of intrusion detection agents. A new detection language, with special focus on simplicity, usability and maintenance, was specified to model DEMIAN monitoring agents. A new correlation language, with a functional and analytical foundation, was defined to model the high-level threat analyst agent. Finally, all communication activities between agents were separated from monitoring and threat analysis tasks and modelled in an independent and interoperable way. This new approach to model the communication between agents integrates main standardization efforts on agent communication languages and intrusion detection formats: FIPA―ACL standard for Agent Communication Language and the Intrusion Detection Working Group IDMEF format. This integration is one of the main accomplishments of our work. In DEMIAN, we don't need to define a unique modelling language that supports all possible aspects of an attack language. With our approach, its possible to specify the behavior of different types of agents with different languages, and maintain the system fully integrated as long as all agents communicate with the same language and understand the same vocabulary.
机译:本文介绍了一种用于入侵检测的小型代理系统,DEMIAN系统有助于模拟入侵检测代理的行为和通信的新知识规范方法。一种新的检测语言,特别注重简单,可用性和维护,指定了模拟Demian Monitoring代理。具有功能和分析基础的新相关语言被定义为模拟高级威胁分析师代理。最后,代理之间的所有通信活动与监测和威胁分析任务分开,并以独立和可互操作的方式建模。这种模拟代理商之间的通信的新方法集成了代理通信语言和入侵检测格式的主要标准化工作:代理通信语言的FIPA-ACL标准和入侵检测工作组IDMEF格式。这种整合是我们工作的主要成就之一。在Demian中,我们不需要定义一个唯一的建模语言,支持攻击语言的所有可能的方面。通过我们的方法,可以使用不同语言指定不同类型的代理的行为,并将系统完全集成,只要所有代理与相同的语言通信并理解相同的词汇。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号