An agent-based distributed framework for intrusion detection using mobile shared memory

  • Authors:
  • Mohammad Allahbakhsh;Hamid Reza Motahari Nezhad

  • Affiliations:
  • Computer Department, Faculty of Engineering, University of Zabol, Zabol, Iran;Computer Department, Faculty of Engineering, University of Zabol, Zabol, Iran

  • Venue:
  • AIC'06 Proceedings of the 6th WSEAS International Conference on Applied Informatics and Communications
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Increasing reliance of society, companies,... on networked information systems has prompted interest in making the information systems secure and dependable, so that they continue to perform their functions even in the presence of vulnerabilities susceptible to malicious attacks. To enable vulnerable systems to survive attacks, it is necessary to detect attacks and isolate failures resulting from attacks before they damage the system. In this filed of study the most important problems are: • Detecting in-progress attacks before they cause damage instead of detecting attacks after they have succeeded, • Minimizing damage by isolating attacked components in real-time and • Tracing the origin of attacks. We address the detection problem by real-time event monitoring and comparison against events known to be unacceptable. Our presented framework is composed of several parts that each other has a defined duty and is implemented using a specific method and technology. Using this framework, you can specify your security policy independent of the algorithm that you will use for detecting every type of intrusion. This framework is light-weight, dependable, fault tolerant, simple to implement and is defined based on new technology of intelligent agents and a new type of shared memory called mobile shared memory. Theses attributes differentiates our presented framework from other works.