Detecting anomalous data is essential to obtain critical and actionable information such as intrusions, faults, and system failures. In this paper an agent-based clustering algorithm to detect anomalies in a distributed system, is introduced. Each data object, independently of which source it arrives, is associated with a mobile agent following the flocking algorithm, a self-organizing bio-inspired computational model. The agents are randomly disseminated onto a virtual space where they move in order to form a flock. Thanks to a tailored similarity function the agents that are associated with similar objects form a flock, whereas the agents that are associated with objects dissimilar (outliers/anomalies) to each other do not group in flocks. Preliminarily experimental results confirm the validity of the proposed approach.

A multi-agent approach for intrusion detection in distributed systems

Forestiero A
2015

Abstract

Detecting anomalous data is essential to obtain critical and actionable information such as intrusions, faults, and system failures. In this paper an agent-based clustering algorithm to detect anomalies in a distributed system, is introduced. Each data object, independently of which source it arrives, is associated with a mobile agent following the flocking algorithm, a self-organizing bio-inspired computational model. The agents are randomly disseminated onto a virtual space where they move in order to form a flock. Thanks to a tailored similarity function the agents that are associated with similar objects form a flock, whereas the agents that are associated with objects dissimilar (outliers/anomalies) to each other do not group in flocks. Preliminarily experimental results confirm the validity of the proposed approach.
2015
Istituto di Calcolo e Reti ad Alte Prestazioni - ICAR
Inglese
Multimedia Communications, Services and Security
International Conference on Multimedia Communications, Services and Security
72
82
http://www.scopus.com/inward/record.url?eid=2-s2.0-84952683308&partnerID=q2rCbXpz
November 24, 2015
Krakow
Anomaly detection
Distributed systems
Multi-agents
Self-organizing
1
none
Forestiero A.
273
info:eu-repo/semantics/conferenceObject
04 Contributo in convegno::04.01 Contributo in Atti di convegno
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/341331
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? 1
social impact