首页> 外文期刊>Journal of Engineering & Applied Sciences >Mobile Agents for Intrusion Detection System Based on A New Anomaly Approach
【24h】

Mobile Agents for Intrusion Detection System Based on A New Anomaly Approach

机译:基于新异常方法的移动入侵检测系统代理

获取原文
获取原文并翻译 | 示例
           

摘要

The aim of this study is to present the performance of an agent approach for intelligent and distributed intrusion detection system based on a new anomaly detection. The performance is investigated in terms of detection delay, false alarm rate and detection rate by comparing the presented two versions MAFIDS_v1 (Mobile Agents for Intrusion Detection System) and MAFIDS_v2, respectively based on a basic statistical anomaly detection algorithm (an adaptive threshold algorithm) and a modified adaptive threshold algorithm. This novel framework incorporates parameters issued from the investigation of 2 notions: morphology and artificial emotion. The underlying idea is to describe state of agent organization by various measurements made at the agent level. A particular emphasis is on the incorporation of these measurements to the anomaly detection algorithm for detecting SYN flooding, the most common type of Denial of Service (DOS) attack and improve its performance over actuations of real TCP traffic especially when the major shortcomings of anomaly detection are: a longer detection and higher false alarm rate.
机译:这项研究的目的是介绍一种基于新异常检测的智能分布式分布式入侵检测系统代理方法的性能。通过比较提出的两种版本的MAFIDS_v1(入侵检测系统的移动代理)和MAFIDS_v2,分别基于基本的统计异常检测算法(自适应阈值算法)和检测延迟,误报率和检测率,对性能进行了研究。改进的自适应阈值算法。这个新颖的框架结合了从两个概念的研究中得出的参数:形态学和人工情感。基本思想是通过在代理级别进行的各种度量来描述代理组织的状态。特别要强调的是将这些测量值合并到异常检测算法中,以检测SYN泛洪,最常见的拒绝服务(DOS)攻击类型,并在激活实际TCP流量时提高其性能,特别是在异常检测的主要缺点时分别是:更长的检测时间和更高的误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号