Multi-agent Peer-to-Peer Intrusion Detection
نویسندگان
چکیده
Ever increasing use of heterogeneous networks including mobile devices and ad-hoc sensor networks signifies the role of such information system properties as openness, autonomy, cooperation, coordination, etc. Agent-based service-oriented Peer-to-Peer (P2P) architecture provides attractive (if not single) design and implementation paradigm for such systems. This trend implies coherent evolution of security systems, what put in use the notions of distributed security policy, distributed intrusion detection systems, etc.1, requiring novel ideas. The paper proposes new architecture for such security systems. This architecture provides cooperative performance of distributed security means (agents) supported by distributed meta-knowledge base implemented as an overlay network of instances of P2P agent platform set up on top of P2P networking provider. The paper also analyzes new issues of P2P security systems with the main attention to P2P training of security agents to correlation of alerts produced by other relevant agents. An artificially built case study is used to highlight the essence of P2P security agent training to P2P decision combining and to exhibit new problems.
منابع مشابه
Intrusion Detection in Open Peer-to-Peer Multi-Agent Systems
One way to build large-scale autonomous systems is to develop open peer-to-peer architectures in which peers are not pre-engineered to work together and in which peers themselves determine the social norms that govern collective behaviour. A major practical limitation to such systems is security because the very openness of such systems negates most traditional security solutions. We propose a ...
متن کاملEnhancing the Survivability of Intrusion Detection Agents through Port Switching and Peer-to-peer Replication
Security applications such as intrusion detection software often lack a security-conscious design that supports their vigilance goal. Similarly, software generation tools and libraries typically lack security constructs that support the development more robust systems. The latter is the case of agent-generation frameworks, which are rarely designed to guarantee agents a safe, continuous functio...
متن کاملPeer-to-Peer Intrusion Detection Systeme für den Schutz sensibler IT-Infrastrukturen
Peer-to-Peer (P2P) Systeme haben sich zu einer viel versprechenden Alternative für die Gestaltung von Anwendungen im Internet entwickelt. Die zunehmende Dezentralisierung von Intrusion Detection Systemen sowie der verstärkte Einsatz in mobilen Umgebungen legt die Nutzung des Peer-to-Peer-Prinzips auch für Intrusion Detection Systeme nahe. Erste Ansätze zu P2P Intrusion Detection Systemen wurden...
متن کاملCollaborative Intrusion Detection Framework: Characteristics, Adversarial Opportunities and Countermeasures
Complex Internet attacks may come from multiple sources, and target multiple networks and technologies. Nevertheless, Collaborative Intrusion Detection Systems (CIDS) emerges as a promising solution by using information frommultiple sources to gain a better understanding of objective and impact of complex Internet attacks. CIDS also help to cope with classical problems of Intrusion Detection Sy...
متن کاملPeer Pressure in Smoking and its Impact on Social Welfare; A Study Using Agent-based Modeling and Simulation
Many people die each year due to smoking. Social pressures, such as peer pressure, which are manifested in one's interactions with his/her peers, are from very effective factors in people's tendency to smoke. In this research, it was attempted to study and analyze peer pressure in smoking and its impact on some of the welfare indicators including mortality number due to starvation, wealth avera...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007