Search In this Thesis
   Search In this Thesis  
العنوان
Intrusion Detection Correlation in Computer Network Using Multi-Agent System\
الناشر
Ain Shams university.
المؤلف
Taha ,Ayman Elsayed Elsayed.
هيئة الاعداد
مشرف / Ayman Mohamed Bahaa
مشرف / il Abdel Ghafar Farag
مشرف / Hani M. K. Mahdi
باحث / an Elsayed Elsayed Taha
الموضوع
Computer Network. Multi-Agent System Intrusion Detection Correlation.
تاريخ النشر
2011
عدد الصفحات
p.:172
اللغة
الإنجليزية
الدرجة
الدكتوراه
التخصص
الهندسة الكهربائية والالكترونية
تاريخ الإجازة
1/1/2011
مكان الإجازة
جامعة عين شمس - كلية الهندسة - Computer and Systems Engineering
الفهرس
Only 14 pages are availabe for public view

from 185

from 185

Abstract

The thesis purpose is to prove the possibility of improving both IDS Accuracy and IDS Completeness through reducing either False Positive or False Negative alerts using correlation between different available information sources in the system and network environment. The dissertation presents a modular framework for a Distributed Agent Correlation Model (DACM) for intrusion detection alerts and events in computer networks. The framework introduces a multi-agent distributed model in a hierarchical organization; correlates alerts from the IDS with attack signatures from information security tools and either system or application log files as other sources of information. The model has been implemented and tested using a set of datasets. Agent’s proposed models and algorithms have been implemented, analyzed, and evaluated to measure detection and correlation rates and reduction of false positive and false negative alerts. In conclusion, DACM enhances both the accuracy and completeness of intrusion detection compared with other published papers in same field. DACM is flexible, upgradable, and platform independent. It decreases the audit load and the time cost required to obtain effective situational understanding; Finally, DACM can be used as a real time system with minor modifications.