| Previous | [ 1] | [ 2] | [ 3] | [ 4] | [ 5] | [ 6] | [ 7] | [ 8] | [ 9] | [ 10] | [ 11] | [ 12] | [ 13] | [ 14] | [ 15] | [ 16] | [ 17] | [ 18] | [ 19] |
¡@
Han-Pang Huang1,2, Feng-Cheng Yang1, Ming-Tzong Wang1 and Chia-Ming Chang2
1Graduate Institute of Industrial Engineering
2Department of Mechanical Engineering
National Taiwan University
Taipei, 106 Taiwan
E-mail: {hanpang; iefcyang}@ntu.edu.tw
The network security is getting more important due to the wide-spread computer
viruses and increasing network attacks. Nowadays, more and more security mechanisms,
such as firewalls and intrusion detection systems (IDS), are introduced to protect the
network from malicious attacks. This paper proposes an agent and service based intrusion
detection and response system for active network. In contrast to a traditional passive
network, an active network gives the nodes programmable ability to exercise various active
network technologies. The intrusion response, service deployment, and service update
mechanisms are centered on this technology. The proposed model of intrusion detection
and response system (IDRS) catches network attacks and responses to stop the
attacks at the first time to reduce the damage. Detecting, reporting, and responding capabilities
are all embedded and integrated in the proposed system. A prototype system is
developed using a novel data mining technology (the support vector machine) to enhance
the detection function. In addition, several experiments were conducted to verify the
system and results showed that the system was able to effectively identify the intrusions
and respond promptly. Experiments also showed that the support vector machine outperforms
the competitive neural networks in identifying the intrusions.
Received July 23, 2007; revised October 17, 2007; accepted November 22, 2007.
Communicated by Tsan-sheng Hsu.