Adaptive agent-based intrusion response /
A new methodology has been developed for adaptive, automated intrusion response (IR) focusing on the role of software agents in providing that response. The majority of intrusion response systems (IRSs) react to attacks by generating reports or alarms. This introduces a window of vulnerability bet...
| Main Author: | |
|---|---|
| Format: | Thesis Book |
| Language: | English |
| Published: |
[Place of publication not identified] :
[publisher not identified] ;
2001.
|
| Subjects: | |
| Online Access: | http://proxy.library.tamu.edu/login?url=http://proquest.umi.com/pqdweb?did=728907731&sid=1&Fmt=2&clientId=2945&RQT=309&VName=PQD |
| Summary: | A new methodology has been developed for adaptive, automated intrusion response (IR) focusing on the role of software agents in providing that response. The majority of intrusion response systems (IRSs) react to attacks by generating reports or alarms. This introduces a window of vulnerability between when a intrusion is detected and when action is taken to defend against the attack. This window of vulnerability has been reduced through an agent-based system that adaptively responds to intrusions. Multiple IDSs monitor a computer system and generate intrusion alarms. Interface agents maintain a model of each IDS based on the number of false positives/negatives previously generated. It uses this model to generate an attack confidence metric and passes this metric along with the intrusion alarm to the Master Analysis agent. The Master Analysis agent classifies whether the incident is a continuation of an existing incident or is a new attack. If it is a new attack, the Master Analysis agent creates a new Analysis agent to develop a response plan to the new attack. If the incident is a continuation of an existing attack, the Master Analysis agent passes the attack confidence metric and intrusion alarm to the existing Analysis agent handling the attack. The Analysis agent analyzes an incident until it is resolved and generates a course of action to resolve the incident. To generate this course of action, the Analysis agent invloves the Response Taxonomy agent to classify the attack and Policy Specification agent to limit the response based on legal, ethical, institutional, or resource constraints. The Analysis agent creates a course of action and then invokes the appropriate components of the Response Toolkit. The Analysis agents employ adaptive decision-making based on the success of previous responses. As decisions are made, the results are displayed to the user interface. This research presents a novel IR methodology that includes: response adaptation to intrusive behavior based on confidence in the intrusion detection mechanism; response adaptation to intrusive behavior based on the success of previous intrusion responses; and synergistic support for multiple IDSs. |
|---|---|
| Item Description: | Vita. "Major Subject: Computer Science". |
| Physical Description: | xiv, 162 leaves : illustrations ; 28 cm. + 1 CD ROM Issued also on microfiche from University Microfilm Inc. |
| Bibliography: | Includes bibliographical references (leaves 113-123). |