JISE


  [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19]


Journal of Information Science and Engineering, Vol. 25 No. 3, pp. 843-859


Intrusion Detection Based on Active Networks


Han-Pang Huang1,2, Feng-Cheng Yang1, Ming-Tzong Wang1 and Chia-Ming Chang2
1Graduate Institute of Industrial Engineering 
2Department of Mechanical Engineering 
National Taiwan University 
Taipei, 106 Taiwan 
E-mail: {hanpang; iefcyang}@ntu.edu.tw


    The network security is getting more important due to the wide-spread computer viruses and increasing network attacks. Nowadays, more and more security mechanisms, such as firewalls and intrusion detection systems (IDS), are introduced to protect the network from malicious attacks. This paper proposes an agent and service based intrusion detection and response system for active network. In contrast to a traditional passive network, an active network gives the nodes programmable ability to exercise various active network technologies. The intrusion response, service deployment, and service update mechanisms are centered on this technology. The proposed model of intrusion detection and response system (IDRS) catches network attacks and responses to stop the attacks at the first time to reduce the damage. Detecting, reporting, and responding capabilities are all embedded and integrated in the proposed system. A prototype system is developed using a novel data mining technology (the support vector machine) to enhance the detection function. In addition, several experiments were conducted to verify the system and results showed that the system was able to effectively identify the intrusions and respond promptly. Experiments also showed that the support vector machine outperforms the competitive neural networks in identifying the intrusions.


Keywords: active network, intrusion detection, SVM, BPNN, network security

  Retrieve PDF document (JISE_200903_12.pdf)