The proliferation of wireless communication and mobile computing is driving the emergence of Mobile Ad hoc Networks (MANETs) with wide application ranges from civilian environment to military communication. However, securing MANETs is a highly challenging issue due to their inherent characteristics. Intrusion detection is an important security
mechanism, but little effort has been directed towards efficient and effective architectures for Intrusion Detection System (IDS) in the context of MANETs. We investigate existing IDS architecture design issues, and propose a novel mobile agent based IDS architecture that has each node implementing basic IDS functions, while ranger agents roam the network executing more advanced IDS functions. This is suited to MANETs because it avoids the single point of failure problem, minimises communication overheads at the same time as providing up to date information for intrusion decisions.