{"title":"An agent based architecture using ontology for intrusion detection system","authors":"M. Bist, A. P. Panwar, Vishwas Kumar","doi":"10.1109/NGCT.2016.7877481","DOIUrl":null,"url":null,"abstract":"Intrusion Detection Systems is one of the most useful tools which are used nowadays to identify the attacks happening on the network. But the high false positive and false negative rates are major limitations in Intrusion detection System. To overcome these limitations new techniques should be introduced. In our research we used Ontology in Intrusion Detection System. As Ontology describes the semantic relations between entities, we used this technique in our system to describe the attacks by their behavior. Our proposed Intrusion Detection System contains multiple agents like Sniffer agent, Analysis Agent, communication agent and manager agent. They work collectively to detect the intrusion in a much efficient way. Analysis agent uses ontology to identify the attack. Protege is software which creates ontology. Our system semantically analyses various fields of the packet and infer to a solution about attack. To identify complex attacks occurs in distributed environment that are not identified by the existing systems we are using complex attack ontology. So overall Ontology based Intrusion Detection Systems are much advanced as compared to other IDS as these are reliable, scalable, interoperable and helpful for finding new attacks.","PeriodicalId":326018,"journal":{"name":"2016 2nd International Conference on Next Generation Computing Technologies (NGCT)","volume":"37 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 2nd International Conference on Next Generation Computing Technologies (NGCT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NGCT.2016.7877481","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Intrusion Detection Systems is one of the most useful tools which are used nowadays to identify the attacks happening on the network. But the high false positive and false negative rates are major limitations in Intrusion detection System. To overcome these limitations new techniques should be introduced. In our research we used Ontology in Intrusion Detection System. As Ontology describes the semantic relations between entities, we used this technique in our system to describe the attacks by their behavior. Our proposed Intrusion Detection System contains multiple agents like Sniffer agent, Analysis Agent, communication agent and manager agent. They work collectively to detect the intrusion in a much efficient way. Analysis agent uses ontology to identify the attack. Protege is software which creates ontology. Our system semantically analyses various fields of the packet and infer to a solution about attack. To identify complex attacks occurs in distributed environment that are not identified by the existing systems we are using complex attack ontology. So overall Ontology based Intrusion Detection Systems are much advanced as compared to other IDS as these are reliable, scalable, interoperable and helpful for finding new attacks.