Project information
Reflective-Cognitive Adaptation for Network Intrusion Detection Systems
(CAMNEP II)
- Project Identification
- W911NF-08-1-0250
- Project Period
- 6/2008 - 12/2009
- Investor / Pogramme / Project type
-
U.S. Army RDECOM Acquisition Center
- U.S. Army RDECOM Acq Ctr Projects
- MU Faculty or unit
-
Institute of Computer Science
- Ing. Jiří Novotný
- doc. Ing. Pavel Čeleda, Ph.D.
- RNDr. Vojtěch Krmíček, Ph.D.
- Keywords
- intrusion detection, network behavior analysis, multi-agent system, trust, anomaly detection, programable hardware
- Cooperating Organization
-
Czech Technical University Prague
- Responsible person doc. Ing. Michal Pěchouček, M.Sc.
The goal of the CAMNEP II project is to combine the high-bandwidth network traffic acquisition devices with distributed and adaptive multi-agent system to deliver a concept of efficient, effective and self-managing Network Intrusion Detection System (NIDS). This system would be deployed on backbone links of one or more network operators in order to detect malicious traffic, minimizing the rate of false positives/negatives that renders current systems less effective. Attack detection process will rely on cooperation between a community of trusting agents, each specialized in one aspect of traffic characteristics. We aim to further reduce the system operational costs by providing basic self-adaptation capabilities, using the coordination methods from multi-agent field and adaptive software/hardware in traffic acquisition layer. The system operation and adaptation will be supervised and regulated via advanced user interface, that would proactively seek additional information for each incident and will also allow policy specification.
Publications
Total number of publications: 6
2011
-
Optimizing flow sampling for network anomaly detection
Wireless Communications and Mobile Computing Conference (IWCMC), 2011 7th International, year: 2011
2009
-
Adaptive Multiagent System for Network Traffic Monitoring
IEEE Intelligent Systems, year: 2009, volume: 24, edition: 3
-
Collaborative approach to network behaviour analysis based on hardware-accelerated FlowMon probes
International Journal of Electronic Security and Digital Forensics, year: 2009, volume: 2, edition: 1
-
Flow Based Security Awareness Framework for High-Speed Networks
Security and Protection of Information 2009, year: 2009
2008
-
Flow Based Network Intrusion Detection System using Hardware-Accelerated NetFlow Probes
CESNET Conference 2008 : security, middleware, and virtualization – glue of future networks, year: 2008
-
Improving Anomaly Detection Error Rate by Collective Trust Modeling
Recent Advances in Intrusion Detection, year: 2008