Multi-Agents based Architecture for IS Security Incident Reaction

Benjamin Gateau, Christophe Feltus, Djamel Khadraoui, Benoît de Remont

Research output: Contribution in Book/Catalog/Report/Conference proceedingConference contribution

91 Downloads (Pure)

Abstract

The main focus of this paper is to provide a global architectural solution built on the requirements for a reaction after alert detection mechanisms in the frame of Information Systems Security and more particularly applied to telecom infrastructures security. These infrastructures are distributed in nature, therefore the targeted architecture is developed in a distributed perspective and is composed of three basic layers: low level, intermediate level and high level. The low level is dedicated to be the interface between the main architecture and the targeted infrastructure. The intermediate level is responsible of correlating the alerts coming from different domains of the infrastructure and to deploy smartly the reaction actions. This intermediate level is elaborated using multi-agents system that provide the advantages of autonomous and interaction facilities. The high level permits to have a supervision view of the whole infrastructure, and to manage business policy definition. The proposed approach has been successfully experimented for data access control mechanism.
Original languageEnglish
Title of host publicationProceedings of RIVF'08 : IEEE International Conference on Research, Innovation and Vision for the Future in Computing & Communication Technologies, Ho Chi Minh, Vietnam.
Publication statusPublished - 2008

Keywords

  • Multi-agents systems
  • Architecture
  • Security Policy
  • Distributed networks

Fingerprint

Dive into the research topics of 'Multi-Agents based Architecture for IS Security Incident Reaction'. Together they form a unique fingerprint.

Cite this