False Alarm Reduction Using Adaptive Agent-Based Profiling

Publisher: IGI Global_journal

E-ISSN: 1930-1669|7|4|53-74

ISSN: 1930-1650

Source: International Journal of Information Security and Privacy (IJISP), Vol.7, Iss.4, 2013-10, pp. : 53-74

Disclaimer: Any content in publications that violate the sovereignty, the constitution or regulations of the PRC is not accepted or approved by CNPIEC.

Previous Menu Next

Abstract

In this paper the authors propose a new efficient anomaly-based intrusion detection mechanism based on multi-agent systems. New networks are particularly vulnerable to intrusion, they are often attacked with intelligent and skilful hacking techniques. The intrusion detection techniques have to deal with two problems: intrusion detection and false alarms. The issue of false alarms has an important impact on the success of the anomaly-based intrusion detection technologies. The purpose of this paper is to improve their accuracy by detecting real attacks and by reducing the number of unnecessary generated alerts. The authors' intrusion detection mechanism relies on a set of agents to ensure the detection and the adaptation of normal profile to support the legitimate dynamic changes that occur and are the cause of high rate of false alarms.