A log analyzer agent for intrusion detection in a multi-agent system

  • Authors:
  • Iago Porto-Díaz;Óscar Fontenla-omero;Amparo Alonso-etanzos

  • Affiliations:
  • Department of Computer Science, University of A Coruña, Spain;Department of Computer Science, University of A Coruña, Spain;Department of Computer Science, University of A Coruña, Spain

  • Venue:
  • KES'10 Proceedings of the 14th international conference on Knowledge-based and intelligent information and engineering systems: Part I
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this work, the design and implementation of a log analyzer agent is described. This agent is conceived to act as a part of a multi-agent Intrusion Detection System. The agent analyzes log files of services, applications or operating systems contrasting every log line with a set of security rules defined by experts. These rules can be created using a new easy to use XML-based format founded on an object-oriented model. Whenever a security match is found, the agent sends a security report to the next level of the multi-agent system using the IDMEF (Intrusion Detection Message Exchange Format) and the IDXP (Intrusion Detection Exchange Protocol).