A Multi-agent Case-Based Reasoning Intrusion Detection System Prototype

被引:1
作者
Schoenborn, Jakob Michael [1 ,2 ]
Althoff, Klaus-Dieter [1 ,2 ]
机构
[1] Univ Hildesheim, Univ Pl 1, D-31141 Hildesheim, Germany
[2] German Res Ctr Artificial Intelligence DFKI, Trippstadter Str 122, D-67663 Kaiserslautern, Germany
来源
CASE-BASED REASONING RESEARCH AND DEVELOPMENT, ICCBR 2023 | 2023年 / 14141卷
关键词
Case-based Reasoning; SEASALT; Intrusion Detection System; Multi-Agent System;
D O I
10.1007/978-3-031-40177-0_23
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The number of actors, costs, and incidents in terms of internet criminality is rising each year as many devices in our daily routines become increasingly connected to the internet. 'Security by design' is gaining increased awareness in software engineering, but it is not to be expected to catch all security issues as the range of potential security issues and the creativity of the attackers are both seemingly endless. Thus, we propose a multi-agent case-based reasoning system to detect malicious traffic in a computer network. We mainly rely on the commonly used UNSW_NB15 data set including 82332 training cases with mostly numeric attributes, but the application design is open to operate with other data sources, such as NSL-KDD and CICIDS-2017 as well. Purpose. The aim of the proposed system is to detect malicious network traffic and alert the security engineer of a company to take further actions such as blocking the source IP address of the potential attacker. Findings. We were able to successfully detect seven out of ten attacks with an average true-positive rate of 82,56% and leave the remaining attacks (Analysis, Backdoor, Worms) for further investigation and improvements. Implications and value. The results are close to other research results with room for improvement. Due to the nature of a multi-agent framework, this application could be integrated into other existing intrusion detection systems and serve as an add-on.
引用
收藏
页码:359 / 374
页数:16
相关论文
共 50 条
[41]   CBR-PDS: a case-based reasoning phishing detection system [J].
Hassan Abutair ;
Abdelfettah Belghith ;
Saad AlAhmadi .
Journal of Ambient Intelligence and Humanized Computing, 2019, 10 :2593-2606
[42]   Using Case-Based Reasoning for Phishing Detection [J].
Abutair, Hassan Y. A. ;
Belghith, Abdelfettah .
8TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT-2017) AND THE 7TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT 2017), 2017, 109 :281-288
[43]   Multi-agent Decision Making Based on Evidence Reasoning [J].
Fan, Bo ;
Pu, Jiexin ;
Liu, Gang .
FIRST IITA INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2009, :70-73
[44]   The Use of Case-Based Reasoning in Creating a Prototype for Electromagnetic Device Optimization [J].
Ouyang, Jun ;
Lowther, David A. .
IEEE TRANSACTIONS ON MAGNETICS, 2010, 46 (08) :3377-3380
[45]   Risk prediction in surgery using case-based reasoning and agent-based modelization [J].
Perez, Bruno ;
Lang, Christophe ;
Henriet, Julien ;
Philippe, Laurent ;
Auber, Frederic .
COMPUTERS IN BIOLOGY AND MEDICINE, 2021, 128
[46]   A case-based reasoning system for fault detection and isolation: a case study on complex gearboxes [J].
Boral, Soumava ;
Chaturvedi, Sanjay Kumar ;
Naikan, V. N. A. .
JOURNAL OF QUALITY IN MAINTENANCE ENGINEERING, 2019, 25 (02) :213-235
[47]   A case-based reasoning system for software reuse [J].
Shubita A.F. ;
Edais S.M. .
International Journal of Applied Systemic Studies, 2020, 9 (01) :31-44
[48]   A Case-based Reasoning System for Mechanical Design [J].
Liu Jia-li ;
Yan Xiang-bin ;
Qi Wei ;
Li Yi-jun .
2008 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE & ENGINEERING (15TH), VOLS I AND II, CONFERENCE PROCEEDINGS, 2008, :585-590
[49]   MACE-SCM: A multi-agent and case-based reasoning collaboration mechanism for supply chain management under supply and demand uncertainties [J].
Kwon, Ohbyung ;
Im, Ghi Paul ;
Lee, Kun Chang .
EXPERT SYSTEMS WITH APPLICATIONS, 2007, 33 (03) :690-705
[50]   Towards a Validtime Case-Based Reasoning System [J].
Tanawong, Tawin ;
Chittayasothorn, Suphamit .
WMSCI 2008: 12TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL VI, PROCEEDINGS, 2008, :179-182