Second generation of Multi-agent heterogeneous intrusion detection system (M-AHIDS) is a prototype proposed to detect untrusted and unusual network behaviour. The M-AHIDS is based on online traffic statistics in sFlow format acquired by network device with the sFlow agent and is able to perform a real-time surveillance of the 10 Gb networks. However, after an immense reimplementation it is capable to process also offline data set from DARPA Intrusion Detection Evaluation Data Set and KDD99 Cup data set. Offline data sets are used for the correct comparison with another IDSs. The main contribution of the system is the integration of several anomaly detection techniques, new future state prognostic and new machinery of multi-agent temporal logic with hybrid argumentation. Every detection technique is represented by featuring a specific detection autonomous agent. At this stage, every agent determines the flow trustfulness from aggregated connection. The anomalies are used as an input for machinery of multi-agent temporal logic which is represented by the logical agent. M-AHIDS is already partially implemented, tested and modified accordingly for more than three years.
Multi-agent heterogeneous intrusion detection system (MAHIDS) is a prototype proposed to detect untrusted and unusual network behaviour. The main contribution of the system is the integration of several anomaly detection techniques and machinery of multi-agent temporal logic with hybrid argumentation. Every detection technique is represented by featuring a specific detection autonomous agent. In this stage, every agent determines the flow trustfulness from aggregated connection. The anomalies are used as an input for machinery of multiagent temporal logic which is represented by the logical agent. The logical agent is one of the system’s advantages because it has huge capabilities for making a right decision about intrusions from detected anomalies. Another significant advantage of M-AHIDS is a new innovative agent – Web agent. The Web agent is capable to detect trusted host from his activity on web pages. The system M-AHIDS is based on traffic statistics in sFlow format acquired by network device with sFlow agent and is able to perform a real-time surveillance of the 10 Gb networks.
Abstrakt: Sledovanie používatel’a internetu a analyzovanie jeho správania sa je čoraz častejším javom. Jednou zo základných techník sledovania používatel’a je stopovanie jeho webového prehliadača. V tomto článku predstavíme teoretické východiská, rozoberieme niekol’ko základných techník a predstavíme vlastný systém na detekciu odtlačkov prehliadačov a histórie nimi navštívených stránok s ciel’om čo najpresnejšie identifikovat’ používatel’a internetu. Pri tvorení systému na deanonymizáciu sme kládli dôraz na jednoduchost’ implementačného riešenia založeného na bežných webových technológiách ako PHP, CSS, JavaSript a Flash. Ciel’om predstavovaného výskumu je ako využit’ jeho výsledky v oblasti bezpečnosti (ochrana súkromia či ochrana systémov pred kyber útokmi) , tak aj využit’ nazbierané dáta pre dôkladnejšiu analýzu návštevnosti web stránok. Na overenie navrhnutého systému sme tento nasadili na stránky Univerzity Komenského v Bratislave a jej fakultách, čo nám umožnilo nazbierat’ dostatočné množstvo dát a v konečnom dôsledku zároveň pomohlo získat’ dôležité informácie o návštevnosti a správaní sa používatel’ov na jednotlivých stránkach univerzity. Ako ukazujú výsledky nášho výskumu, identifikovanie používatel’a cez jeho prehliadač, či zistenie jeho histórie, môže uskutočnit’ l’ubovol’ná web stránka. Za sledované jednomesačné obdobie sme boli schopní jednoznačne identifikovat’ 75.74% z 225 154 prehliadačov a 10.01% prehliadačov umožnilo detekciu histórie.