TY - JOUR T1 - Mobile Agents for Intrusion Detection System Based on A New Anomaly Approach AU - Ghedira, Khaled AU - Kadhi, Nabil El AU - Barika Ktata, Farah JO - Journal of Engineering and Applied Sciences VL - 6 IS - 1 SP - 79 EP - 90 PY - 2011 DA - 2001/08/19 SN - 1816-949x DO - jeasci.2011.79.90 UR - https://makhillpublications.co/view-article.php?doi=jeasci.2011.79.90 KW - anomaly KW -distributed intrusion detection system KW -Agent approach KW -detection KW -morphology KW -morphology AB - The aim of this study is to present the performance of an agent approach for intelligent and distributed intrusion detection system based on a new anomaly detection. The performance is investigated in terms of detection delay, false alarm rate and detection rate by comparing the presented two versions MAFIDS_v1 (Mobile Agents for Intrusion Detection System) and MAFIDS_v2, respectively based on a basic statistical anomaly detection algorithm (an adaptive threshold algorithm) and a modified adaptive threshold algorithm. This novel framework incorporates parameters issued from the investigation of 2 notions: morphology and artificial emotion. The underlying idea is to describe state of agent organization by various measurements made at the agent level. A particular emphasis is on the incorporation of these measurements to the anomaly detection algorithm for detecting SYN flooding, the most common type of Denial of Service (DOS) attack and improve its performance over uctuations of real TCP traffic especially when the major shortcomings of anomaly detection are: a longer detection and higher false alarm rate. ER -