dc.contributor.author |
Chatzigiannakis, V |
en |
dc.contributor.author |
Androulidakis, G |
en |
dc.contributor.author |
Grammatikou, M |
en |
dc.contributor.author |
Maglaris, B |
en |
dc.date.accessioned |
2014-03-01T02:42:26Z |
|
dc.date.available |
2014-03-01T02:42:26Z |
|
dc.date.issued |
2004 |
en |
dc.identifier.uri |
https://dspace.lib.ntua.gr/xmlui/handle/123456789/31011 |
|
dc.relation.uri |
http://www.scopus.com/inward/record.url?eid=2-s2.0-12244266088&partnerID=40&md5=9f3bbd1fb3f6e3cc9e54872e1258ff52 |
en |
dc.relation.uri |
http://www.informatik.uni-trier.de/~ley/db/conf/csreaSAM/csreaSAM2004.html#ChatzigiannakisAGM04 |
en |
dc.relation.uri |
http://www.netmode.ntua.gr/papers/gandr/SAM04-netmode.pdf |
en |
dc.subject |
Central Management |
en |
dc.subject |
Distributed Intrusion Detection |
en |
dc.subject |
IDMEF data model |
en |
dc.subject |
Rate Limiting |
en |
dc.subject |
Smart Agents |
en |
dc.subject.other |
Computer hardware |
en |
dc.subject.other |
Demodulation |
en |
dc.subject.other |
Intercom systems |
en |
dc.subject.other |
Local area networks |
en |
dc.subject.other |
Network protocols |
en |
dc.subject.other |
Problem solving |
en |
dc.subject.other |
Sensors |
en |
dc.subject.other |
Anti-virus programs |
en |
dc.subject.other |
Distributed intrusion detection |
en |
dc.subject.other |
Network systems |
en |
dc.subject.other |
Smart agents |
en |
dc.subject.other |
Intelligent agents |
en |
dc.title |
An architectural framework for distributed intrusion detection using smart agents |
en |
heal.type |
conferenceItem |
en |
heal.publicationDate |
2004 |
en |
heal.abstract |
Intrusion Detection Systems (IDS) have been developed to solve the problem of detecting the attacks on several network systems. In small-scale networks a single IDS is sufficient to detect attacks but this is inadequate in large-scale networks, where the number of packets across the network is enormous. In this paper, we present an Architectural Framework considering the large-scale network environment. We designed and implemented a Distributed Intrusion Detection system that relies on Smart Agents which monitor network traffic and report intrusion alerts to a central management node. Distribution is handled through the introduction of multiple sensors and the use of Smart Agents who are responsible for reporting and rate limiting of messages. Finally, we extended the IDMEF (Intrusion Detection Message Exchange Format) data model to support digital signatures and to strengthen the authentication of the system. |
en |
heal.journalName |
Proceedings of the International Conference on Security and Management, SAM'04 |
en |
dc.identifier.spage |
193 |
en |
dc.identifier.epage |
199 |
en |