A self-organising multi-agent system for decentralised forensic investigations

被引:6
作者
Kendrick, Phillip [1 ]
Criado, Natalia [2 ]
Hussain, Abir [1 ]
Randles, Martin [1 ]
机构
[1] John Moores Univ, Liverpool L3 3AF, Merseyside, England
[2] Kings Coll London, London WC2R 2LS, England
关键词
Multi-agent systems; Cyber security; Network forensics; INTRUSION DETECTION;
D O I
10.1016/j.eswa.2018.02.023
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As network-based threats continue to evolve more rapidly, detecting and responding to intrusion attempts in real-time requires an increasingly automated and intelligent response. This paper provides an agent-based framework for the analysis of cyber events within networks of varying sizes to detect complex multi-stage attacks. Agents are used as intelligent systems to explore domain specific and situational information showing the benefit of adaptive technologies that proactively analyse security events in real time. We introduce several algorithms to encapsulate and manage the traditional detection technologies and provide agent-based performance introspection as a mechanism to identify poorly performing systems. Our evaluation shows that the algorithms can reduce the amount of processing needed to analyse a security event by over 50% and improve the detection rate by up to 20% by introducing corrective systems to reduce false alarm rates in error-prone environments. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:12 / 26
页数:15
相关论文
共 33 条
[1]  
Alsubhi K., 2011, 2011 IFIP/IEEE International Symposium on Integrated Network Management (IM 2011), P369, DOI 10.1109/INM.2011.5990713
[2]  
[Anonymous], 30 ISECOM
[3]  
[Anonymous], 2010, WORKING NOTES 2010 A
[4]  
[Anonymous], TECHNICAL REPORT
[5]  
[Anonymous], 2015, Journal of Big Data, DOI DOI 10.1186/S40537-015-0013-4
[6]  
[Anonymous], 2002, International Journal of Digital Evidence, DOI DOI 10.1109/SADFE.2009.8
[7]  
[Anonymous], 2013, INT J DATABASE THEOR, DOI DOI 10.14257/IJDTA.2013.6.5.01
[8]  
[Anonymous], IJJCAI INT JOINT C A
[9]   Multi-agent systems for protecting critical infrastructures: A survey [J].
Baig, Zubair A. .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2012, 35 (03) :1151-1161
[10]   Sudden trust collapse in networked societies [J].
Batista, Joao da Gama ;
Bouchaud, Jean-Philippe ;
Challet, Damien .
EUROPEAN PHYSICAL JOURNAL B, 2015, 88 (03) :1-11