Defending a Computer System Using Autonomous Agents

Mark Crosbie, Eugene H. Spafford · Purdue e-Pubs (Purdue University System) · 1995

This report presents a prototype architecture of a defense mechanism for computer systems. The intrusion detection problem is introduced and some of the key aspects of any solution are explained. Standard intrusion detection systems are built as a single monolithic module. A finer-grained approach is proposed, where small, independent agents monitor the system. These agents are taught how to recognise intrusive behaviour. The learning mechanism in the agents is built using Genetic Programming. This is explained, and some sample agents are described. The flexibility, scalability and resilience of the agent approach are discussed. Future issues are also outlined. 1 Introduction Because of increased network connectivity, computer systems are becoming increasingly vulnerable to attack. These attacks often exploit flaws in either the operating system or application programs. The general goal of such attacks is to subvert the traditional security mechanisms on the systems so as to execute o...

Read the paper · More papers on PaperTik