Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1109/IAT.2007.59acmconferencesArticle/Chapter ViewAbstractPublication PagesiatConference Proceedingsconference-collections
Article

High-Speed Network Traffic Acquisition for Agent Systems

Published: 02 November 2007 Publication History

Abstract

This paper presents a design of high-speed network traffic acquisition subsystem suitable for agent-based intrusion detection systems. To match the performance requirements and to improve network traffic measurement, wire-speed data acquisition layer is based on hardware-accelerated probes, which provide real-time network traffic statistics. The network traffic is stored in collector servers and preprocessed data is then sent to detection agents that use heterogenous anomaly detection methods. These methods are correlated by means of trust and reputation models, and the conclusions regarding the maliciousness of the traffic is presented to the operator. Presented system is designed to improve the performance of agent-based intrusion detection systems and allow them to efficiently identify malicious traffic. The main contribution of presented system is its ability to aggregate real-time network-wide statistics from geographically dispersed probes. Traffic acquisition system is designed for deployment on high-speed backbone networks.

Cited By

View all
  • (2013)Limitations of a Mapping Algorithm with Fragmentation Mimics (MAFM) when modeling statistical data sources based on measured packet network trafficComputer Networks: The International Journal of Computer and Telecommunications Networking10.1016/j.comnet.2013.07.03257:17(3686-3700)Online publication date: 1-Dec-2013
  • (2011)FSP and FLTL framework for specification and verification of middle-agentsInternational Journal of Applied Mathematics and Computer Science10.2478/v10006-011-0001-621:1(9-25)Online publication date: 1-Mar-2011

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
IAT '07: Proceedings of the 2007 IEEE/WIC/ACM International Conference on Intelligent Agent Technology
November 2007
527 pages
ISBN:0769530273

Sponsors

Publisher

IEEE Computer Society

United States

Publication History

Published: 02 November 2007

Check for updates

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)1
  • Downloads (Last 6 weeks)0
Reflects downloads up to 09 Nov 2024

Other Metrics

Citations

Cited By

View all
  • (2013)Limitations of a Mapping Algorithm with Fragmentation Mimics (MAFM) when modeling statistical data sources based on measured packet network trafficComputer Networks: The International Journal of Computer and Telecommunications Networking10.1016/j.comnet.2013.07.03257:17(3686-3700)Online publication date: 1-Dec-2013
  • (2011)FSP and FLTL framework for specification and verification of middle-agentsInternational Journal of Applied Mathematics and Computer Science10.2478/v10006-011-0001-621:1(9-25)Online publication date: 1-Mar-2011

View Options

Get Access

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media