Header menu link for other important links
X
Intelligent multi-agent based database hybrid intrusion prevention system
P. Ramasubramanian,
Published in Springer Verlag
2004
Volume: 3255
   
Pages: 393 - 408
Abstract
This paper describes a framework for highly distributed real-time monitoring approach to database security using Intelligent Multi-Agents. The intrusion prevention system described in this paper uses a combination of both statistical anomaly prevention and rule based misuse prevention in order to detect a misuser. The statistical anomaly prediction system employs ensemble Quickprop neural networks forecasting model, which predicts unauthorized invasions of user based on previous observations and takes further action before intrusion occurs. The experimental study is performed using real data provided by a major Corporate Bank. A comparative evaluation of the two ensemble networks over the individual networks was carried out using mean absolute percentage error on a prediction data set and a better prediction accuracy has been observed. The Misuse Prevention system uses a set of rules that define typical illegal user behavior. A separate rule subsystem is designed for this misuse detection system and it is known as Temporal Authorization Rule Markup Language (TARML). In order to reduce single point of failures in centralized security system, a dynamic distributed system has been designed in which the security management task is distributed across the network using Intelligent Multi-Agents. © Springer-Verlag Berlin Heidelberg 2004.