Intrusion Detection Based on Active Networks
Journal
Journal of Information Science and Engineering
Journal Volume
25
Journal Issue
3
Pages
843-859
Date Issued
2009
Abstract
The network security is getting more important due to the wide-spread computer viruses and increasing network attacks. Nowadays, more and more security mechanisms, such as firewalls and intrusion detection systems (IDS), are introduced to protect the network from malicious attacks. This paper proposes an agent and service based intru-sion detection and response system for active network. In contrast to a traditional passive network, an active network gives the nodes programmable ability to exercise various ac-tive network technologies. The intrusion response, service deployment, and service up-date mechanisms are centered on this technology. The proposed model of intrusion de-tection and response system (IDRS) catches network attacks and responses to stop the attacks at the first time to reduce the damage. Detecting, reporting, and responding capa-bilities are all embedded and integrated in the proposed system. A prototype system is developed using a novel data mining technology (the support vector machine) to enhance the detection function. In addition, several experiments were conducted to verify the system and results showed that the system was able to effectively identify the intrusions and respond promptly. Experiments also showed that the support vector machine out-performs the competitive neural networks in identifying the intrusions.
Type
journal article
