PAID: A Probabilistic Agent-Based Intrusion Detection system

被引:30
作者
Gowadia, V [1 ]
Farkas, C [1 ]
Valtorta, M [1 ]
机构
[1] Univ S Carolina, Dept Comp Sci & Engn, Informat Secur Lab, Columbia, SC 29208 USA
基金
美国国家科学基金会;
关键词
intrusion detection; network security; computer security; computer attack; agents; Bayesian networks;
D O I
10.1016/j.cose.2005.06.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we describe architecture and implementation of a Probabilistic Agent-Based Intrusion Detection (PAID) system. The PAID system has a cooperative agent architecture. Autonomous agents can perform specific intrusion detection tasks (e.g., identify IP-spoofing attacks) and also collaborate with other agents. The main contributions of our work are the following: our model allows agents to share their beliefs, i.e., the probability distribution of an event occurrence. Agents are capable to perform soft-evidential update, thus providing a continuous scale for intrusion detection. We propose methods for modelling errors and resolving conflicts among beliefs. Finally, we have implemented a proof-of-concept prototype of PAID. (C) 2005 Elsevier Ltd. All rights reserved.
引用
收藏
页码:529 / 545
页数:17
相关论文
共 40 条
[1]  
[Anonymous], 2002, FIPA ACL MESS STRUCT
[2]  
[Anonymous], 2002, P LOND COMM S
[3]  
[Anonymous], 1999, Probabilistic Networks and Expert Systems
[4]  
[Anonymous], 2000, INTRUSION DETECTION
[5]  
ASAKA M, 1999, P 11 ANN FIRST C COM
[6]  
BALASUBRAMANIYA.J, 1998, ARCHITECTURE INTRUSI
[7]  
Barbara D, 2001, P 1 SIAM C DAT MIN
[8]  
Bellifemine F., 1999, P 4 INT C EXH PRACT
[9]  
BLOEMEKE M, 2002, 2002006 U S CAR DEP
[10]  
BRAY T, 2001, EXTENSIBLE MARKUP LA