Node-Based System for Optimizing the Process of Creation ff Intelligent Agents for Intrusion Detection and Analysis
Iva Marinova, Vladimir Jotsov · 2018
In recent days Intrusion Detection Systems (IDS) become more popular and more sophisticated solutions are used to process raw network traffic and prevent attacks of all types. With the growth of the global network and the dark web, known attack types increase too and common network intrusion detection systems have to update their signatures on a daily basis to keep up with the current threats. But what about Zero-day attacks. There is always a period of hours and sometimes days or even years like in the case of "Meltdown" and "Spectre" vulnerabilities, when the hack is not known to the public. Contemporary IDS systems need to be aware of a Zero-day attacks and one way to accomplish this is to use machine learning or deep learning to create intelligent agents in the form of predictive models capable to predict whether unseen data is of attack type or not. But every corporate environment is different and we know that these kinds of agents are very dependent on the environment. One predictive model is not usable in a new network system, which makes the development and design of the predictive models expensive and client specific. That's why we propose a system which main goal is to automate the process of designing and training a predictive model for network intrusion detection and classification/analysis. The agent's autonomy depends on its modeling capabilities. Puzzle method standards and constraints have been proposed aiming to automate this process.