Active defense of a computer system using autonomous agents (1995) [33 citations — 0 self]
Abstract:
This report presents a prototype architecture for an active defense mechanism for computer systems. The intrusion detection problem is introduced and some of the key aspects of any solution are explained. Previous attempts to use similar techniques are discussed, and their shortcomings are explained. A new architecture is proposed which uses Genetic Programming to evolve programs to detect anomalous behaviour in a system. This architecture is developed and evaluated. A sample genetic program is used to discuss some of the design aspects of the agents. Cooperative monitoring of NFS requests shows how the approach can be generalised. The discussion details some issues to be addressed and future research directions.
Citations
| 5172 | Genetic Algorithms – Goldberg - 1989 |
| 1877 | Genetic Programming: On the Programming of Computers by Means of Natural Selection – Koza - 1992 |
| 155 | Modeling adaptive autonomous agents – Maes - 1994 |
| 105 | A Pattern Matching Model for Misuse Intrusion Detection – Kumar, Spafford - 1994 |
| 53 | TCP WRAPPER: Network monitoring, access control and booby traps – Venema - 1992 |
| 49 | Artificial intelligence and intrusion detection: Current and future directions – Frank - 1994 |
| 42 | The architecture of a network level intrusion detection system – Heady, Luger, et al. - 1990 |
| 7 | How to Use DLPI – Nuckolls - 1992 |
| 5 | et al. A Real-time Intrusion-Detection Expert – Lunt, Javitz, et al. - 1992 |
| 1 | A Biologically Inspired Immune System for Computers. High Integrity Computing – Kephart - 1994 |

