Volume no :2, Issue no: 2, May 2009

AGENT IDS BASED ON MISUSE APPROACH

Author's: F. A. Barika, N. El Kadhi and K. Ghédira
Pages: [287] - [317]
Received Date: December 4, 2008
Submitted by:

Abstract

In this paper, we aim at presenting an implementation of a new agent IDS (Intrusion Detection System) model, based on misuse approach.
Through its ease to detect simulated attacks, we show that the use of mobile agents has practical advantages for intrusion detection. Based on a set of simulated intrusions, we established a comparative experimental study of four IDSs, showing that most of current IDS are generally centralized and suffer from significant limitations when used in high speed networks, especially when they face distributed attacks. This leads us to use distributed model based on mobile agents paradigm. We believe that agent will help collecting efficient and useful information for IDS.

Keywords

intrusion detection system, agent IDS, misuse approach, attacks simulation, distributed attack.