An ontology-based multiagent architecture for outbound intrusion detection
Salvador Mandujano, Arturo Galván, Juan A. Nolazco‐Flores · 2005
Summary form only given. The advantages of using knowledge representation and management techniques in information security have been already identified by some researchers, however, little has been done to enable security technologies with them. We present an ontology-based multiagent architecture that implements outbound intrusion detection, a monitoring approach that aims at guaranteeing that local systems are not used to compromise others. The specific goal is to identify automated attack tools, which constitute a public, unexplored repository of software security information. An attacker-centric ontology supports the architecture. Agents organized into teams execute on trusted sub-environments called cells, which are in turn organized non-hierarchically. Cells perform two independent misuse detection strategies whose output is further correlated to provide a third, more accurate diagnosis. Ontology and signature updates are deployed over the Internet as a way to speed up incident response.