International Journal of Computational Intelligence Systems (Aug 2008)

Attack Pattern Analysis Framework for a Multiagent Intrusion Detection System

  • Grzegorz Kolaczek,
  • Krzysztof Juszczyszyn

DOI
https://doi.org/10.2991/ijcis.2008.1.3.3
Journal volume & issue
Vol. 1, no. 3

Abstract

Read online

The paper proposes the use of attack pattern ontology and formal framework for network traffic anomalies detection within a distributed multi-agent Intrusion Detection System architecture. Our framework assumes ontology-based attack definition and distributed processing scheme with exchange of communicates between agents. The role of traffic anomalies detection was presented then it has been discussed how some specific values characterizing network communication can be used to detect network anomalies caused by security incidents (worm attack, virus spreading). Finally, it has been defined how to use the proposed techniques in distributed IDS using attack pattern ontology.

Keywords