Multi-agent technologies for computer network security: Attack simulation, intrusion detection and intrusion detection learning

Vladimir Ivanovich Gorodetski, Igor Vitalievich Kotenko, Oleg Vladislavovich Karsaev · 2003

During the last few years the computer network security remains a problem of great concern within information technology research area. Increase of network scale, development of advanced information technologies, and other factors enhance the number of possible targets for attacks against computer networks. These factors negatively influence upon the efficiency of the existing computer networks security systems and enable research and development of new protection models and technologies. Along with the conventionally used security tools like firewalls, intrusion detection systems (IDSs) are becoming of supreme significance. It is well known that modern realtime IDSs are not able to detect sophisticated attacks performed by professionals. Newly invented attacks are realized as coordinated distributed operations of groups of professionals; they are carried out from different locations, through different entry points, and at different time moments. On the other hand, IDS often interprets normal operation of a computer network as hostile actions thus producing many false alarms. A considerable improvement of IDS efficiency could be achieved in case of using knowledge obtained from generalization and formalization of accumulated experience regarding computer system vulnerabilities and attack cases. This is a cogent argument for the necessity of deep study and research of essence and peculiarities of coordinated distributed attacks. The study cannot be only restricted by generalization of the experience; it has also to be based on using

Read the paper · More papers on PaperTik