TY - GEN
T1 - Towards a multiagent-based distributed Intrusion Detection System using data mining approaches
AU - Brahmi, Imen
AU - Ben Yahia, Sadok
AU - Aouadi, Hamed
AU - Poncelet, Pascal
PY - 2012
Y1 - 2012
N2 - The system that monitors the events occurring in a computer system or a network and analyzes the events for sign of intrusions is known as Intrusion Detection System (IDS). The IDS need to be accurate, adaptive, and extensible. Although many established techniques and commercial products exist, their effectiveness leaves room for improvement. A great deal of research has been carried out on intrusion detection in a distributed environment to palliate the drawbacks of centralized approaches. However, distributed IDS suffer from a number of drawbacks e.g., high rates of false positives, low efficiency, etc. In this paper, we propose a distributed IDS that integrates the desirable features provided by the multi-agent methodology with the high accuracy of data mining techniques. The proposed system relies on a set of intelligent agents that collect and analyze the network connections, and data mining techniques are shown to be useful to detect the intrusions. Carried out experiments showed superior performance of our distributed IDS compared to the centralized one.
AB - The system that monitors the events occurring in a computer system or a network and analyzes the events for sign of intrusions is known as Intrusion Detection System (IDS). The IDS need to be accurate, adaptive, and extensible. Although many established techniques and commercial products exist, their effectiveness leaves room for improvement. A great deal of research has been carried out on intrusion detection in a distributed environment to palliate the drawbacks of centralized approaches. However, distributed IDS suffer from a number of drawbacks e.g., high rates of false positives, low efficiency, etc. In this paper, we propose a distributed IDS that integrates the desirable features provided by the multi-agent methodology with the high accuracy of data mining techniques. The proposed system relies on a set of intelligent agents that collect and analyze the network connections, and data mining techniques are shown to be useful to detect the intrusions. Carried out experiments showed superior performance of our distributed IDS compared to the centralized one.
KW - Anomaly Detection
KW - Data Mining Techniques
KW - Intrusion Detection System
KW - Misuse Detection
KW - Multi-agents
U2 - 10.1007/978-3-642-27609-5_12
DO - 10.1007/978-3-642-27609-5_12
M3 - Article in proceedings
AN - SCOPUS:84255170687
SN - 9783642276088
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 173
EP - 194
BT - Agents and Data Mining Interaction - 7th International Workshop, ADMI 2011, Revised Selected Papers
PB - Springer
T2 - 7th International Workshop on Agents and Data Mining Interaction, ADMI 2011
Y2 - 2 May 2011 through 6 May 2011
ER -