Applying mobile agents to intrusion detection and response

Wayne Jansen, Peter Mell, Tom Karygiannis, Don Marks · 1999

security problems and developed a simple security policy for applets.Mitre Corporation [FARM96, FARM97] also pursued work in this area, developing authentication mechanisms and defining a taxonomy of security related problems.An important observation to make about most of the early work in this field is the assumption made by most researchers about a totally open system.Thatis, the security problems being addressed are those found in a system with open connectivity and with the maximum possible threats.Several researchers reached conclusions indicating that the paradigm was not useful since there were always certain threats that could not be adequately countered while maintaining a totally open system.Partly because of these conclusions, as well as well publicized attacks against early Java- enabled systems, security related problems have hindered the widespread adoption of MA technology.Security architectures have been defined, but they contain too much residual risk for most applications.Recent work at the University of Tulsa, for example, proposes using mobile agents for data mining purposes.Such an application requires providers of information to keep their systems "open" to a multitude of users, most of whom are unknown to the host.A good overview of current mobile agent projects and technology is provided in [MARR98].However, relatively little work has been done on using a mobile agent architecture for the purpose of providing a security capability, such as intrusion detection.If a mobile agent architecture is designed for a specific purpose such as system administration or security function maintenance, then strong authentication may be enforced and the residual risk decreases significantly.While MAs are an extraordinarily powerful tool, their implementation has been hindered by security considerations.These security considerations are especially critical for intrusion detection systems, with the result that most security research in this field has concentrated upon the architecture necessary to provide security for mobile agents.We claim that such negative results are not fatal to the proposed study since these security issues are likely to be addressed by the research community and there will be few authorized users of the MA-based IDSs within an organization.1.3.

Read the paper · More papers on PaperTik