A Multi-agent Case-Based Reasoning Intrusion Detection System Prototype

被引:1
作者
Schoenborn, Jakob Michael [1 ,2 ]
Althoff, Klaus-Dieter [1 ,2 ]
机构
[1] Univ Hildesheim, Univ Pl 1, D-31141 Hildesheim, Germany
[2] German Res Ctr Artificial Intelligence DFKI, Trippstadter Str 122, D-67663 Kaiserslautern, Germany
来源
CASE-BASED REASONING RESEARCH AND DEVELOPMENT, ICCBR 2023 | 2023年 / 14141卷
关键词
Case-based Reasoning; SEASALT; Intrusion Detection System; Multi-Agent System;
D O I
10.1007/978-3-031-40177-0_23
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The number of actors, costs, and incidents in terms of internet criminality is rising each year as many devices in our daily routines become increasingly connected to the internet. 'Security by design' is gaining increased awareness in software engineering, but it is not to be expected to catch all security issues as the range of potential security issues and the creativity of the attackers are both seemingly endless. Thus, we propose a multi-agent case-based reasoning system to detect malicious traffic in a computer network. We mainly rely on the commonly used UNSW_NB15 data set including 82332 training cases with mostly numeric attributes, but the application design is open to operate with other data sources, such as NSL-KDD and CICIDS-2017 as well. Purpose. The aim of the proposed system is to detect malicious network traffic and alert the security engineer of a company to take further actions such as blocking the source IP address of the potential attacker. Findings. We were able to successfully detect seven out of ten attacks with an average true-positive rate of 82,56% and leave the remaining attacks (Analysis, Backdoor, Worms) for further investigation and improvements. Implications and value. The results are close to other research results with room for improvement. Due to the nature of a multi-agent framework, this application could be integrated into other existing intrusion detection systems and serve as an add-on.
引用
收藏
页码:359 / 374
页数:16
相关论文
共 50 条
[1]   A Multi-Agent Case-Based Reasoning Architecture for Phishing Detection [J].
Abutair, Hassan Y. A. ;
Belghith, Abdelfettah .
14TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2017) / 12TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC 2017) / AFFILIATED WORKSHOPS, 2017, 110 :492-497
[2]   Multi-agent Clinical Decision Support System using Case-Based Reasoning [J].
Korablyov, Mykola ;
Axak, Natalia ;
Fomichov, Oleksandr ;
Hnidenko, Volodymyr .
COLINS 2021: COMPUTATIONAL LINGUISTICS AND INTELLIGENT SYSTEMS, VOL I, 2021, 2870
[3]   A Survey of Multi-agent Systems and Case-Based Reasoning Integration [J].
Jubair, Mohammed Ahmed ;
Mostafa, Salama A. ;
Mustapha, Aida ;
Hafit, Hanayanti .
2018 INTERNATIONAL SYMPOSIUM ON AGENTS, MULTI-AGENT SYSTEMS AND ROBOTICS (ISAMSR 2018), 2018,
[4]   Dynamic control for safety system multi-agent system with case-based reasoning [J].
Aissani N. ;
Guetarni I.H.M. ;
Zebirate S. .
International Journal of Reliability and Safety, 2017, 11 (3-4) :238-255
[5]   Integrating Multi-Agent System and Case-Based Reasoning for Flood Early Warning and Response System [J].
Rashid, Nor Aimuni Md ;
Abidin, Zaheera Zainal ;
Abas, Zuraida Abal .
INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (12) :479-488
[6]   Emerging medical informatics with case-based reasoning for aiding clinical decision in multi-agent system [J].
Ying, Shen ;
Joel, Colloc ;
Armelle, Jacquet-Andrieu ;
Kai, Lei .
JOURNAL OF BIOMEDICAL INFORMATICS, 2015, 56 :307-317
[7]   Multi-agent based hybrid Intrusion detection system [J].
Zhang, Bao-Jun ;
Pan, Xue-Zeng ;
Wang, Jie-Bing ;
Ping, Ling-Di .
Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2009, 43 (06) :987-993+1162
[8]   A deep learning-based multi-agent system for intrusion detection [J].
Louati, Faten ;
Ktata, Farah Barika .
SN APPLIED SCIENCES, 2020, 2 (04)
[9]   A deep learning-based multi-agent system for intrusion detection [J].
Faten Louati ;
Farah Barika Ktata .
SN Applied Sciences, 2020, 2
[10]   Towards a Multi-Agent based Network Intrusion Detection System for a Fleet of Drones [J].
Ouiazzane, Said ;
Barramou, Fatimazahra ;
Addou, Malika .
INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (10) :351-362