Journal of Software, Vol 4, No 6 (2009), 495-507, Aug 2009
doi:10.4304/jsw.4.6.495-507

Agent IDS based on Misuse Approach

Farah Barika Ktata, Nabil El Kadhi, Khaled Ghédira

Abstract


Most current IDS are generally centralized andsuffer from significant limitations when used in high speednetworks, especially when they face distributed attacks. Thispaper shows that the use of mobile agents has practical advantagesfor intrusion detection. For this purpose we carriedout a comparative experimental study of some IDS, showingtheir limits and then we propose an implementation of a newMAFIDS (Mobile Agent for Intrusion Detection System)model focusing on misuse approach. The performance ofMAFIDS is investigated in terms of detection delay, falsealarm and detection rate by comparing it to a centralizedIDS over real traffic and a set of simulated attacks.



Keywords


Mobile Agents, Intrusions Detection System,Misuse Approach, Detection Delay, False Alarm, DetectionRate

References



Full Text: PDF


Journal of Software (JSW, ISSN 1796-217X)

Copyright @ 2006-2012 by ACADEMY PUBLISHER – All rights reserved.