Abstract

Most of intrusion detection systems nowadays are not really distributed systems which cannot detect the distributed or cooperative attacks effectively. In this paper, an agent-based distributed cooperative model (ADCM) is proposed, which implements cooperative intrusion detection through efficient, normative event messages exchange among logic detection domains (LDD). Some specific detection agents are also presented which are independent separately, while they can communicate and cooperate with one another to take actions. The ADCM improves the ability of error tolerance and cooperation without degradation of efficiency. Prototype of a distributed intrusion detection system based on ADCM and the extended intrusion detection message exchange format is completed, which proves to be powerful as expected in detecting intrusions.

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.