A Multi-agent Case-Based Reasoning Intrusion Detection System Prototype

被引:1
作者
Schoenborn, Jakob Michael [1 ,2 ]
Althoff, Klaus-Dieter [1 ,2 ]
机构
[1] Univ Hildesheim, Univ Pl 1, D-31141 Hildesheim, Germany
[2] German Res Ctr Artificial Intelligence DFKI, Trippstadter Str 122, D-67663 Kaiserslautern, Germany
来源
CASE-BASED REASONING RESEARCH AND DEVELOPMENT, ICCBR 2023 | 2023年 / 14141卷
关键词
Case-based Reasoning; SEASALT; Intrusion Detection System; Multi-Agent System;
D O I
10.1007/978-3-031-40177-0_23
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The number of actors, costs, and incidents in terms of internet criminality is rising each year as many devices in our daily routines become increasingly connected to the internet. 'Security by design' is gaining increased awareness in software engineering, but it is not to be expected to catch all security issues as the range of potential security issues and the creativity of the attackers are both seemingly endless. Thus, we propose a multi-agent case-based reasoning system to detect malicious traffic in a computer network. We mainly rely on the commonly used UNSW_NB15 data set including 82332 training cases with mostly numeric attributes, but the application design is open to operate with other data sources, such as NSL-KDD and CICIDS-2017 as well. Purpose. The aim of the proposed system is to detect malicious network traffic and alert the security engineer of a company to take further actions such as blocking the source IP address of the potential attacker. Findings. We were able to successfully detect seven out of ten attacks with an average true-positive rate of 82,56% and leave the remaining attacks (Analysis, Backdoor, Worms) for further investigation and improvements. Implications and value. The results are close to other research results with room for improvement. Due to the nature of a multi-agent framework, this application could be integrated into other existing intrusion detection systems and serve as an add-on.
引用
收藏
页码:359 / 374
页数:16
相关论文
共 50 条
[21]   Designing Intelligent Tutoring Systems: A Personalization Strategy using Case-Based Reasoning and Multi-Agent Systems [J].
Gonzalez, Carolina ;
Burguillo, Juan Carlos ;
Llamas, Martin ;
Laza, Rosalia .
ADCAIJ-ADVANCES IN DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE JOURNAL, 2013, 2 (01) :41-53
[22]   Design of a fault-tolerant mechanism for multi-agent based intrusion detection system [J].
Yi, MK ;
Baik, MS ;
Hwang, CS .
SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, :190-196
[23]   Real-time multi-agent system for an adaptive intrusion detection system [J].
Al-Yaseen, Wathiq Laftah ;
Othman, Zulaiha Ali ;
Nazri, Mohd Zakree Ahmad .
PATTERN RECOGNITION LETTERS, 2017, 85 :56-64
[24]   A combined multi-agent and case-based reasoning approach to support collaborative nonconformance problem solving in the thermoplastic injection moulding process [J].
Mikos, Walter Luis ;
Espindola Ferreira, Joao Carlos ;
Correia Gomes, Fabbio Gonzalez ;
Lorenzo, Roman Moura .
INTERNATIONAL JOURNAL OF COMPUTER INTEGRATED MANUFACTURING, 2010, 23 (02) :177-194
[25]   Multi-Agent Intrusion Detection System Using Feature Selection Approach [J].
Gong, Yi ;
Fang, Yong ;
Liu, Liang ;
Li, Juan .
2014 TENTH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING (IIH-MSP 2014), 2014, :528-531
[26]   Multi-agent Cooperative Intrusion Detection Based on Generative Data Augmentation [J].
Liu, Ming ;
Jia, Yungang ;
Li, Chao ;
Fu, Peiguo ;
Zhang, Zhen .
ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT VI, 2024, 14492 :311-328
[27]   Integration of Case Based Reasoning in Multi-agent System for the Real-Time Container Stacking in Seaport Terminals [J].
Rekik, Ines ;
Elkosantini, Sabeur ;
Chabchoub, Habib .
HYBRID ARTIFICIAL INTELLIGENT SYSTEMS, HAIS 2017, 2017, 10334 :435-446
[28]   PERFORMING THE RETRIEVE STEP IN A CASE-BASED REASONING SYSTEM FOR DECISION MAKING IN INTRUSION SCENARIOS [J].
Conesa, Jesus ;
Ribeiro, Angela .
ICEIS 2009 : PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL AIDSS, 2009, :343-346
[29]   A prototype case-based reasoning system for real-time freeway traffic routing [J].
Sadek, AW ;
Smith, BL ;
Demetsky, MJ .
TRANSPORTATION RESEARCH PART C-EMERGING TECHNOLOGIES, 2001, 9 (05) :353-380
[30]   Fuzzy Case-Based Reasoning System [J].
Lu, Jing ;
Bai, Dingling ;
Zhang, Ning ;
Yu, Tiantian ;
Zhang, Xiakun .
APPLIED SCIENCES-BASEL, 2016, 6 (07)