Abstract:Based on investigating immunological principles, the paper presents a multi-agent system for intrusion detection and response in networked computers. The immunity-based agents roam around the nodes, and monitor the situation in the network. These agents can mutually recognize each other's activities, coordinate in a hierarchical fashion, and take appropriate actions according to the underlying security policies. Mobile agents can learn and adapt to the environment dynamically and can detect both known and unknown intrusions. The multi-agent detection system can simultaneously monitor networked computer's activities at different levels, including the user level, system level, process level and packet level. The immunity-based multi-agent intrusion detection system is designed to be flexible, extendible, and adaptable that it can perform real-time monitoring in accordance with the needs and preferences of administrators.