首页> 外文OA文献 >Intelligent multi-agent system for intrusion detection and countermeasures
【2h】

Intelligent multi-agent system for intrusion detection and countermeasures

机译:智能多智能体入侵检测系统及对策

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Intelligent mobile agent systems offer a new approach to implementing intrusion detection systems (IDS). The prototype intrusion detection system, MAIDS, demonstrates the benefits of an agent-based IDS, including distributing the computational effort, reducing the amount of information sent over the network, platform independence, asynchronous operation, and modularity offering ease of updates. Anomaly detection agents use machine learning techniques to detect intrusions; one such agent processes streams of system calls from privileged processes. Misuse detection agents match known problems and correlate events to detect intrusions. Agents report intrusions to other agents and to the system administrator through the graphical user interface (GUI);A sound basis has been created for the intrusion detection system. Intrusions have been modeled using the Software Fault Tree Analysis (SFTA) technique; when augmented with constraint nodes describing trust, contextual, and temporal relationships, the SFTA forms a basis for stating the requirements of the intrusion detection system. Colored Petri Nets (CPN) have been created to model the design of the Intrusion Detection System. Algorithmic transformations are used to create CPN templates from augmented SFT and to create implementation templates from CPNs. The implementation maintains the CPN semantics in the distributed agent-based intrusion detection system.
机译:智能移动代理系统为实现入侵检测系统(IDS)提供了一种新方法。原型入侵检测系统MAIDS展示了基于代理的IDS的优势,包括分配计算量,减少通过网络发送的信息量,平台独立性,异步操作和模块化,从而易于更新。异常检测代理使用机器学习技术来检测入侵。一个这样的代理处理来自特权进程的系统调用流。滥用检测代理可以匹配已知问题并关联事件以检测入侵。代理通过图形用户界面(GUI)向其他代理和系统管理员报告入侵情况;为入侵检测系统创建了良好的基础。入侵已使用软件故障树分析(SFTA)技术建模。当使用描述信任,上下文和时间关系的约束节点进行扩充时,SFTA构成了陈述入侵检测系统要求的基础。已经创建了彩色Petri网(CPN),以对入侵检测系统的设计进行建模。算法转换用于从增强SFT创建CPN模板,并从CPN创建实现模板。该实现在基于分布式代理的入侵检测系统中维护CPN语义。

著录项

  • 作者

    Helmer, Guy Gary;

  • 作者单位
  • 年度 2000
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号