Search In this Thesis
   Search In this Thesis  
العنوان
A Multi Agent-Based Framework for Network Intelligence and Intrusion Prevention
المؤلف
Salah Eldin Abdalaziz,Amani
هيئة الاعداد
باحث / Amani Salah Eldin Abdalaziz
مشرف / Mohamed Shouman
مشرف / Ibrahim Elhenawy
مشرف / Hossam M. Faheem
الموضوع
Attacks and Malwares-
تاريخ النشر
2009
عدد الصفحات
190.p:
اللغة
الإنجليزية
الدرجة
ماجستير
التخصص
Computer Graphics and Computer-Aided Design
تاريخ الإجازة
1/1/2009
مكان الإجازة
اتحاد مكتبات الجامعات المصرية - Science in Computer and Information Science
الفهرس
Only 14 pages are availabe for public view

from 134

from 134

Abstract

World has entered a new age of cyber warfare that threats the survival and reliability of e-business organizations. E-business organizations become more vulnerable to a wide range of threats that aim to break confidentiality, integrity and privileges of network resources. In response to these threats, network security research has become a major concern to organizations throughout the world.
Although the current security solutions have their important roles in securing organizations, they do not provide the accurate protection against the sophisticated threats of today’s cyber-criminals. In this thesis, a Multiagent-Based Intrusion Prevention System is introduced, this system provides the instantaneous in-line layered preemptive protection for network server and hosts against attacks and malwares, with no prior knowledge of their characteristics and signatures. As well, it has the ability of detecting zero-day threats, due to using the behavioral analysis and detection techniques, which focus on the protected entity behavior rather than threats or hackers behaviors, because hackers always use new and creative hacking techniques that can’t be predicted to avoid detection by security solutions.
The proposed system is composed of two multiagent-based frameworks: Server Framework and Host framework. These frameworks operate on different layers in the protected environment to enable detecting threats at earlier stages. Also, using multi-agent technology in developing these frameworks provides more flexible, real-time protection and scalable system, and overcomes the problems of heavy duty on network load and centralized network solutions.