An Ontology-based Multiagent Architecture for Outbound Intrusion Detection

نویسندگان

  • Salvador Mandujano
  • Arturo Galván
  • Juan A. Nolazco
چکیده

Even when the benefits of using knowledge representation and management techniques have been already acknowledged by the intrusion detection community, little has been done to enable security technologies with them. We present an ontology-based multiagent architecture that implements Outbound Intrusion Detection, an intrusion detection approach concerned not with protecting local hosts from being compromised, but with guaranteeing that they are not used to compromise others. The specific aim is to identify automated attack tools which constitute not only a growing threat but also a rich and unexplored security information source. An underlying attacker-centric ontology supports the architecture at the signature generation, signature matching, and agent-communication levels. Agents are organized into teams that execute on trusted sub-environments called agent cells which are in turn organized in a non-hierarchical structure. Cells perform two independent misuse detection strategies whose output is further correlated to provide a third, more accurate security diagnosis. This architecture contemplates antivirus-like signature and ontology deployment over the Internet.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Identifying Attack Code through an Ontology-Based Multiagent Tool: FROID

This paper describes the design and results of FROID, an outbound intrusion detection system built with agent technology and supported by an attacker-centric ontology. The prototype features a misuse-based detection mechanism that identifies remote attack tools in execution. Misuse signatures composed of attributes selected through entropy analysis of outgoing traffic streams and process runtim...

متن کامل

Identifying Attack Code through an Ontology-Based Multiagent Tool: FROID

This paper describes the design and results of FROID, an outbound intrusion detection system built with agent technology and supported by an attacker-centric ontology. The prototype features a misuse-based detection mechanism that identifies remote attack tools in execution. Misuse signatures composed of attributes selected through entropy analysis of outgoing traffic streams and process runtim...

متن کامل

An Ontology-supported Outbound Intrusion Detection System

Outbound intrusion detection is a systems vigilance approach that aims at limiting the effects of a security threat by collectively scrutinizing outgoing traffic and local system activity. This paper summarizes the design and implementation of FROID, an outbound intrusion detection prototype built with agent technology that exploits the semantic power of ontologies in order to enable collaborat...

متن کامل

Attack Pattern Analysis Framework For Multiagent Intrusion Detection System

The paper proposes the use of attack pattern ontology and formal framework for network traffic anomalies detection within a distributed multiagent Intrusion Detection System architecture. Our framework assumes ontology-based attack definition and distributed processing scheme with exchange of communicates between agents. The role of traffic anomalies detection was presented then it has been dis...

متن کامل

Agent Based Distributed Intrusion Detection System (ABDIDS)

This paper introduce (ABDIDS), a simple pattern attack ontology that allows agent based intrusion detection system to detect network traffic anomalies at a higher level more than most current intrusion detection systems do. The cooperative agent architecture has been presented. It has been shown how some attributes in network communication can be used to detect attacks. Finally, the benefits of...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2004