Logo image
Moving towards an adaptive enterprise intrusion detection and prevention system
Conference proceeding

Moving towards an adaptive enterprise intrusion detection and prevention system

Thomas Cole Amick, Lem R Soles and Dallas H. Snider
ICAI 2015: Proceedings of the 2015 International Conference on Artificial Intelligence: WORLDCOMP'15, July 27-30, 2015, Las Vegas, Nevada, USA Vols. 1-2, pp.228-231
International Conference on Artificial Intelligence (Las Vegas, Nevada, USA, 2015)
2015

Metrics

105 Record Views

Abstract

In this paper, we describe our plans to create a smarter network defense system through the collection and analysis of network signatures generated by real security threats. To meet this goal, we plan to create software agents interconnected to a central behavior analysis database service where each software agent records attack meta-information collected during previous intrusion attempts. The central database warehouses and analyzes the meta-information collected by the interconnected agents. The agents can then utilize both instantaneous and historical data by integrating rules derived from the data collection and analysis process into intrusion prevention policies. The result is a modular and scalable network defense system that should be more responsive and adaptable to imminent threats.

Details

Logo image