This paper proposes a fault tolerant distributed intrusion detection system architecture that uses mobile agents. The architecture includes a mobile agent platform (MAP) that provides an execution environment for mobile agents (MAs) to run specialized monitoring tasks. When the main IDS server goes down, the MAP on backup client hosts can collectively take over server responsibilities according to priority. MAs dispatch from the MAP to detect intrusions by invoking filter, correlator and interpreter agents. The paper outlines this architecture and discusses directions for implementing an IDS using the MAP, MAs, detection engines and XML data storage. This approach aims to improve scalability, platform independence and reliability over other IDS models.
Related topics: