A Multi-agent Case-Based Reasoning Intrusion Detection System Prototype

被引:1
|
作者
Schoenborn, Jakob Michael [1 ,2 ]
Althoff, Klaus-Dieter [1 ,2 ]
机构
[1] Univ Hildesheim, Univ Pl 1, D-31141 Hildesheim, Germany
[2] German Res Ctr Artificial Intelligence DFKI, Trippstadter Str 122, D-67663 Kaiserslautern, Germany
来源
CASE-BASED REASONING RESEARCH AND DEVELOPMENT, ICCBR 2023 | 2023年 / 14141卷
关键词
Case-based Reasoning; SEASALT; Intrusion Detection System; Multi-Agent System;
D O I
10.1007/978-3-031-40177-0_23
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The number of actors, costs, and incidents in terms of internet criminality is rising each year as many devices in our daily routines become increasingly connected to the internet. 'Security by design' is gaining increased awareness in software engineering, but it is not to be expected to catch all security issues as the range of potential security issues and the creativity of the attackers are both seemingly endless. Thus, we propose a multi-agent case-based reasoning system to detect malicious traffic in a computer network. We mainly rely on the commonly used UNSW_NB15 data set including 82332 training cases with mostly numeric attributes, but the application design is open to operate with other data sources, such as NSL-KDD and CICIDS-2017 as well. Purpose. The aim of the proposed system is to detect malicious network traffic and alert the security engineer of a company to take further actions such as blocking the source IP address of the potential attacker. Findings. We were able to successfully detect seven out of ten attacks with an average true-positive rate of 82,56% and leave the remaining attacks (Analysis, Backdoor, Worms) for further investigation and improvements. Implications and value. The results are close to other research results with room for improvement. Due to the nature of a multi-agent framework, this application could be integrated into other existing intrusion detection systems and serve as an add-on.
引用
收藏
页码:359 / 374
页数:16
相关论文
共 50 条
  • [31] Towards a Multi-Agent based Network Intrusion Detection System for a Fleet of Drones
    Ouiazzane, Said
    Barramou, Fatimazahra
    Addou, Malika
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (10) : 351 - 362
  • [32] Multi-agent Reinforcement Learning-based Network Intrusion Detection System
    Tellache, Amine
    Mokhtari, Amdjed
    Korba, Abdelaziz Amara
    Ghamri-Doudane, Yacine
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [33] CARDS: Case-Based Reasoning Decision Support Mechanism for Multi-Agent Negotiation in Mobile Commerce
    Lee, Kun Chang
    Lee, Namho
    JASSS-THE JOURNAL OF ARTIFICIAL SOCIETIES AND SOCIAL SIMULATION, 2007, 10 (02):
  • [34] Multi-agent based effective response system for intrusion
    Zhou, Shijie
    Qin, Zhiguang
    Zhang, Feng
    Zhang, Xianfeng
    Liu, Jinde
    Dianzi Keji Daxue Xuebao/Journal of the University of Electronic Science and Technology of China, 2004, 33 (04):
  • [35] Case-Based Multi-Sensor Intrusion Detection
    Schwartz, Daniel G.
    Long, Jidong
    COMPUTATIONAL METHODS IN SCIENCE AND ENGINEERING, VOL 2: ADVANCES IN COMPUTATIONAL SCIENCE, 2009, 1148 : 843 - 846
  • [36] Performance Study of Distributed Multi-Agent Intrusion Detection System
    YIN Yong
    CADDM, 2005, (02) : 38 - 43
  • [37] The multi-agent based fault diagnosis prototype system
    Chen, Z.
    He, Y.
    Chu, F.
    Huang, J.
    Key Engineering Materials, 2001, 204-205 : 287 - 296
  • [38] Integrated Agent-based and Case-based Reasoning System
    Mohamed, A. H.
    ARAB JOURNAL OF NUCLEAR SCIENCES AND APPLICATIONS, 2014, 47 (03): : 24 - 31
  • [39] The multi-agent based fault diagnosis prototype system
    Chen, ZY
    He, YY
    Chu, FL
    Huang, JY
    DAMAGE ASSESSMENT OF STRUCTURES, 2001, 204-2 : 287 - 295
  • [40] A misuse detection agent for intrusion detection in a multi-agent architecture
    Mosqueira-Rey, Eduardo
    Alonso-Betanzos, Amparo
    Baldonedo del Rio, Belen
    Lago Pineiro, Jesus
    AGENT AND MULTI-AGENT SYSTEMS: TECHNOLOGIES AND APPLICATIONS, PROCEEDINGS, 2007, 4496 : 466 - +