Multi-sensor agent-based intrusion detection system

  • Authors:
  • Richard A. Wasniowski

  • Affiliations:
  • California State University, Carson, CA

  • Venue:
  • InfoSecCD '05 Proceedings of the 2nd annual conference on Information security curriculum development
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

The purpose of this paper is to discuss implementation of prototype multi-sensor agent-based intrusion detection system. We assume that it is possible to obtain data in tcpdump format. Using this standard allows a consistent presentation and interpretation of network traffic. We are especially interested in analyzing traffic that has an abnormal or malicious character and should prompt a closer look. In this paper we propose a framework for a multi-sensor agent-based intrusion detection system to support such analyses and response. A specific feature of the model is that the agents use multiple sensors to generate log files. We have developed a prototype based on this framework. This paper discusses also the issues of combining intelligent agent technology with intrusion detection methodology.