【24h】

Collective intrusion detection in wide area networks

机译:广域网中集体入侵检测

获取原文

摘要

We present in this paper a collective approach for intrusion detection in wide area networks. We use the multi-agent paradigm to model the proposed distributed system. In this system, an agent, which plays several roles, is situated on each node of the net. The first role of an agent is to perform the work of a local intrusion detection system (IDS). Periodically, it proceeds to exchange security data within its local neighbouring. The agent neighbouring consists of IDS agents of local neighbour nodes. The goal of such an approach is to consolidate the decision, regarding every suspected security event. Unlike previous works having proposed distributed systems for intrusion detection, our system is not restricted to data sharing. It proceeds in the case of a conflict to a negotiation between neighbouring agents in order to produce a consensual decision. So, the proposed system is fully distributed. It does not require any central or hierarchical control, which compromises its scalability, specially in wide area networks such as Internet. Indeed, in this kind of networks, some attacks like distributed denial of service (DDoS) require fully distributed defence. Experiments on our system show its potential for satisfactory DDoS attack detection.
机译:我们在本文中展示了广域网广域网中的入侵检测的集体方法。我们使用多代理范例来模拟所提出的分布式系统。在该系统中,扮演多个角色的代理位于网络的每个节点上。代理的第一个角色是执行局部入侵检测系统(ID)的工作。定期,它会在其本地邻居内交换安全数据。代理邻居由本地邻居节点的IDS代理组成。这种方法的目标是巩固关于每个疑似安全事件的决定。与以前的作品不同,具有用于入侵检测的分布式系统,我们的系统不限于数据共享。它在与邻近代理人之间的谈判冲突的情况下进行,以产生同意决定。因此,所提出的系统完全分布。它不需要任何中央或分层控制,这损害了其可伸缩性,特别是在诸如Internet之类的广域网中。实际上,在这种网络中,像分布式拒绝服务(DDOS)这样的一些攻击需要完全分布的防御。我们的系统实验表明其令人满意的DDOS攻击检测潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号