Preemptive Distributed Intrusion Detection Using Mobile Agents

  • Authors:
  • P. C. Chan;Victor K. Wei

  • Affiliations:
  • -;-

  • Venue:
  • WETICE '02 Proceedings of the 11th IEEE International Workshops on Enabling Technologies: nfrastructure for Collaborative Enterprises
  • Year:
  • 2002

Quantified Score

Hi-index 0.01

Visualization

Abstract

Distributed intrusion detection systems have many advantages over their centralized counterparts such as scalability, subversion resistance, and graceful service degradation.However, an important disadvantage is their inability to block packets immediately when an intrusion is detected. To tackle this problem, we propose a network-based preemptive distributed intrusion detection system using mobile agents. Packets are diverted to various types of agents strategically placed over the network. Various agents perform tasks in control, detection, policy, and blocking. Suspect packets are blocked before they reach the destination when an intrusion is detected and the policy verdicts for blockage. Ways to mitigate negative impacts of our system on network traffic and latency are discussed.