{"id":{"repo_id":"eastern-wash","oai_identifier":"oai:dc.ewu.edu:theses-1832"},"canonical_url":"https://search.dev.ndltd.org/etd/eastern-wash/oai:dc.ewu.edu:theses-1832","repository":{"repo_id":"eastern-wash","name":"Eastern Washington University","base_url":"https://dc.ewu.edu/do/oai/"},"display":{"title":"Intrusion detection, intelligent agents, and soft computing","abstract":"<p>Demand for intrusion detection systems (IDSs) has increased significantly due to the exponential increase of malignant activities and the shortage of trained network administrators. It is mandatory that an IDS aid network administrators in responding quickly to security threats in order to prevent or minimize damage to computer networks. Conventionally, knowledge-based or rule-based approaches are dominantly used for lntmsion detection tasks. Knowledge construction, especially for probabilistic knowledge, usually requires a large collection of significant representative samples. However, this is not always feasible due to the complex structures of input spaces of intrusive activities (this is the cause of the \"base-fallacy problem''). This is further complicated by the accelerated rate of appearance of new malicious activities. Reviewing the taxonomy of detection approaches (anomaly and signature-based), various sensors (host-based and network-based), and system architecture (stand-alone and distributed), we believe that the ideal IDS should be distributed, intelligent (i.e. perceptual and adaptive) and heterogeneous. Consequently, artificial intelligence approaches are taken within the application domain of intrusion detection in general. LTl particular, a multi-agent system distributed over a computer network consisting of agents with various behaviors is studied. We also consider soft computing approaches due to their ability to handle perceptual information. The results from these agents are aggregated as a group decision. This provides fewer false-positives and improved classification compared to many IDSs that use a single detection method.</p>","abstract_html":"&lt;p&gt;Demand for intrusion detection systems (IDSs) has increased significantly due to the exponential increase of malignant activities and the shortage of trained network administrators. It is mandatory that an IDS aid network administrators in responding quickly to security threats in order to prevent or minimize damage to computer networks. Conventionally, knowledge-based or rule-based approaches are dominantly used for lntmsion detection tasks. Knowledge construction, especially for probabilistic knowledge, usually requires a large collection of significant representative samples. However, this is not always feasible due to the complex structures of input spaces of intrusive activities (this is the cause of the &quot;base-fallacy problem&#x27;&#x27;). This is further complicated by the accelerated rate of appearance of new malicious activities. Reviewing the taxonomy of detection approaches (anomaly and signature-based), various sensors (host-based and network-based), and system architecture (stand-alone and distributed), we believe that the ideal IDS should be distributed, intelligent (i.e. perceptual and adaptive) and heterogeneous. Consequently, artificial intelligence approaches are taken within the application domain of intrusion detection in general. LTl particular, a multi-agent system distributed over a computer network consisting of agents with various behaviors is studied. We also consider soft computing approaches due to their ability to handle perceptual information. The results from these agents are aggregated as a group decision. This provides fewer false-positives and improved classification compared to many IDSs that use a single detection method.&lt;/p&gt;","abstract_has_math":false,"creators":["Miller, Patrick"],"institution":null,"degree_name":"Master of Science (MS) in Computer Science","degree_level":"Thesis: EWU Only","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2003,"date_issued":"2003-01-01T08:00:00Z","date_published":"2003-01-01T08:00:00Z","updated_at":"2026-07-24T02:12:46Z","subjects":["Databases and Information Systems","Information Security","OS and Networks"],"languages":[],"rights":["Access perpetually restricted to EWU users with an active EWU NetID"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://dc.ewu.edu/theses/828","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Miller, Patrick"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis: EWU Only"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MS) in Computer Science"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Databases and Information Systems","Information Security","OS and Networks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["Access perpetually restricted to EWU users with an active EWU NetID"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://dc.ewu.edu/theses/828"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>Demand for intrusion detection systems (IDSs) has increased significantly due to the exponential increase of malignant activities and the shortage of trained network administrators. It is mandatory that an IDS aid network administrators in responding quickly to security threats in order to prevent or minimize damage to computer networks. Conventionally, knowledge-based or rule-based approaches are dominantly used for lntmsion detection tasks. Knowledge construction, especially for probabilistic knowledge, usually requires a large collection of significant representative samples. However, this is not always feasible due to the complex structures of input spaces of intrusive activities (this is the cause of the \"base-fallacy problem''). This is further complicated by the accelerated rate of appearance of new malicious activities. Reviewing the taxonomy of detection approaches (anomaly and signature-based), various sensors (host-based and network-based), and system architecture (stand-alone and distributed), we believe that the ideal IDS should be distributed, intelligent (i.e. perceptual and adaptive) and heterogeneous. Consequently, artificial intelligence approaches are taken within the application domain of intrusion detection in general. LTl particular, a multi-agent system distributed over a computer network consisting of agents with various behaviors is studied. We also consider soft computing approaches due to their ability to handle perceptual information. The results from these agents are aggregated as a group decision. This provides fewer false-positives and improved classification compared to many IDSs that use a single detection method.</p>"]},{"key":"dc:title","label":"Title","values":["Intrusion detection, intelligent agents, and soft computing"]}]}],"canonical_facts":{"dc:creator":["Miller, Patrick"],"dc:description.abstract":["<p>Demand for intrusion detection systems (IDSs) has increased significantly due to the exponential increase of malignant activities and the shortage of trained network administrators. It is mandatory that an IDS aid network administrators in responding quickly to security threats in order to prevent or minimize damage to computer networks. Conventionally, knowledge-based or rule-based approaches are dominantly used for lntmsion detection tasks. Knowledge construction, especially for probabilistic knowledge, usually requires a large collection of significant representative samples. However, this is not always feasible due to the complex structures of input spaces of intrusive activities (this is the cause of the \"base-fallacy problem''). This is further complicated by the accelerated rate of appearance of new malicious activities. Reviewing the taxonomy of detection approaches (anomaly and signature-based), various sensors (host-based and network-based), and system architecture (stand-alone and distributed), we believe that the ideal IDS should be distributed, intelligent (i.e. perceptual and adaptive) and heterogeneous. Consequently, artificial intelligence approaches are taken within the application domain of intrusion detection in general. LTl particular, a multi-agent system distributed over a computer network consisting of agents with various behaviors is studied. We also consider soft computing approaches due to their ability to handle perceptual information. The results from these agents are aggregated as a group decision. This provides fewer false-positives and improved classification compared to many IDSs that use a single detection method.</p>"],"dc:identifier":["https://dc.ewu.edu/theses/828"],"dc:rights":["Access perpetually restricted to EWU users with an active EWU NetID"],"dc:subject":["Databases and Information Systems","Information Security","OS and Networks"],"dc:title":["Intrusion detection, intelligent agents, and soft computing"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis: EWU Only"],"thesis:degree_name":["Master of Science (MS) in Computer Science"]},"updated_at":"2026-07-24T02:12:46Z"}