Adaptive agents applied to intrusion detection

  • Authors:
  • Javier Carbó;Agustín Orfila;Arturo Ribagorda

  • Affiliations:
  • Carlos III University of Madrid, Computer Science Department, Leganés, Madrid, Spain;Carlos III University of Madrid, Computer Science Department, Leganés, Madrid, Spain;Carlos III University of Madrid, Computer Science Department, Leganés, Madrid, Spain

  • Venue:
  • CEEMAS'03 Proceedings of the 3rd Central and Eastern European conference on Multi-agent systems
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes a system of agents that make predictions over the presence of intrusions. Some of the agents act as predictors implementing a given Intrusion Detection model, sniffing out the same traffic. An assessment agent weights the forecasts of such predictor agents, giving a final binary conclusion using a probabilistic model. These weights are continuously adapted according to the previous performance of each predictor agent. Other agent establishes if the prediction from the assessor agent was right or not, sending him back the results. This process is continually repeated and runs without human interaction. The effectiveness of our proposal is measured with the usual method applied in Intrusion Detection domain: Receiver Operating Characteristic curves (detection rate versus false alarm rate). Results of the adaptive agents applied to intrusion detection improve ROC curves as it is shown in this paper.