A New Distributed Intrusion Detection Method Based on Immune Mobile Agent
Intrusion detection system based on mobile agent has overcome the speed-bottleneck problem and reduced network load. Because of the low detection speed and high false positive rate of traditional intrusion detection systems, we have proposed an immune agent by combining immune system with mobile agent. In the distributed intrusion detection systems, the data is collected mostly using distributed component to collect data sent for processing center. Data is often analyzed in the processing center. However, this model has the following problems: bad real time capability, bottleneck, and single point of failure. In order to overcome these shortcomings, a new distributed intrusion detection method based on mobile agent is proposed in this paper by using the intelligent and mobile characteristics of the agent. Analysis shows that the network load can be reduced and the real time capability of the system can be improved with the new method. The system is also robust and fault-tolerant. Since mobile agent only can improve the structure of system, dynamic colonial selection algorithm is adopted for reducing false positive rate. The simulation results on KDD99 data set have shown that the new method can achieve low false positive rate and high detection rate.
Immune agent Mobile agent Network security Distributed intrusion detectiont
Yongzhong Li Chunwei Jing Jing Xu
School of Computer Science and Engineering, Jiangsu University of Science and Technology 212003 Zhen College of Information Engineering, Yancheng Institute of technology,Yancheng, China
国际会议
无锡
英文
233-243
2010-09-17(万方平台首次上网日期,不代表论文的发表时间)