An Early Warning and Orientation System in Network Defense Using Multi-Agents

Fang Wang,Guanzhong Dai,Dejun Mu
DOI: https://doi.org/10.3969/j.issn.1000-2758.2010.06.027
2010-01-01
Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University
Abstract:Traditional network security measures, such as encryption and authentication, firewalls and intrusion detection systems, are effective in the protection of information confidentiality, integrity, usability, and control access, but are still deficient in cooperative defense and early warning. We present a network security defense system using multi-agents which consists of a cooperative early warning and orientation module, a cooperative auditing module, a security isolation module, and an accident recovery module etc. Multi-level hierarchical agents are responsible for communication tasks between modules, and the agent server in the control center is responsible for unified control and cooperation of the security of the entire network. The entire network is divided into different levels of partition, and different levels of the collaborative early warning and orientation system are established. Each partition is self-governing, and through mutual cooperation the partitions jointly maintain the security of the whole network. Test results on IPv6 environment show that this system is effective in early warning, and the capture rate of the intrusion detection systems reaches 95%, the missed alarm rate is decreased to 6%, and the false alarm rate is decreased to 7%.
What problem does this paper attempt to address?