Fuzzy Online Risk Assessment for Distributed Intrusion Prediction and Prevention Systems

被引:13
|
作者
Haslum, Kjetil [1 ]
Abraham, Ajith [1 ]
Knapskog, Svein [1 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Quantifiable Qual Serv Commun Syst, N-7491 Trondheim, Norway
关键词
D O I
10.1109/UKSIM.2008.30
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A Distributed Intrusion Prediction and Prevention Systems (DIPPS) not only detects and prevents possible intrusions but also possesses the capability to predict possible intrusions in a distributed network. Based on the DIPS sensors, instead of merely preventing the attackers or blocking traffic, we propose a fuzzy logic based online risk assessment scheme. The key idea of DIPPS is to protect the network(s) linked to assets, which are considered to be very risky. To implement DIPPS we used a Distributed Intrusion Detection System (DIDS) with extended real time traffic surveillance and online risk assessment. To model and predict the next step of an attacker, we used a Hidden Markov Model (HMM) that captures the interaction between the attacker and the network. The interaction between various DIDS and integration of their output are achieved through a HMM. The novelty of this paper is the detailed development of Fuzzy Logic Controllers to estimate the various risk(s) that are dependent on several other variables based on the inputs from HMM modules and the DIDS agents. To develop the fuzzy risk expert system, if-then fuzzy rules were formulated based on interviews with security experts and network administrators. Preliminary results indicate that such a system is very practical for protecting assets which are prone to attacks or misuse, i.e. highly at risk.
引用
收藏
页码:216 / 223
页数:8
相关论文
共 50 条
  • [1] Online Risk Assessment and Prediction Models For Autonomic Cloud Intrusion Prevention Systems
    Kholidy, Hisham A.
    Erradi, Abdelkarim
    Abdelwahed, Sherif
    Yousof, Ahmed M.
    Ali, Hisham Arafat
    2014 IEEE/ACS 11TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2014, : 715 - 722
  • [2] Distributed Online Risk Assessment in the National Cyberspace
    Karbowski, Andrzej
    ELECTRONICS, 2022, 11 (05)
  • [3] Risk Assessment and Alert Prioritization for Intrusion Detection Systems
    Chakir, El Mostapha
    Moughit, Mohamed
    Idrissi Khamlichi, Youness
    UBIQUITOUS NETWORKING, UNET 2017, 2017, 10542 : 641 - 655
  • [4] A testbed for quantitative assessment of intrusion detection systems using fuzzy logic
    Singaraju, G
    Teo, L
    Zheng, YL
    SECOND IEEE INTERNATIONAL INFORMATION ASSURANCE WORKSHOP, PROCEEDINGS, 2004, : 79 - 93
  • [5] Configuration of intrusion prevention systems based on a legal user: the case for using intrusion prevention systems instead of intrusion detection systems
    Cai, Chuanxi
    Mei, Shue
    Zhong, Weijun
    INFORMATION TECHNOLOGY & MANAGEMENT, 2019, 20 (02): : 55 - 71
  • [6] Configuration of intrusion prevention systems based on a legal user: the case for using intrusion prevention systems instead of intrusion detection systems
    Chuanxi Cai
    Shue Mei
    Weijun Zhong
    Information Technology and Management, 2019, 20 : 55 - 71
  • [7] Application of fuzzy logic for distributed intrusion detection
    Seo, HS
    Cho, TH
    COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 340 - 347
  • [8] An Online Data Access Prediction and Optimization Approach for Distributed Systems
    Ishii, Renato Porfirio
    de Mello, Rodrigo Fernandes
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2012, 23 (06) : 1017 - 1029
  • [9] Dismantling Intrusion Prevention Systems
    Niemi, Olli-Pekka
    Levomaki, Antti
    Manner, Jukka
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2012, 42 (04) : 285 - 286
  • [10] Advanced Reaction Using Risk Assessment in Intrusion Detection Systems
    Kanoun, Wael
    Cuppens-Boulahia, Nora
    Cuppens, Frederic
    Autrel, Fabien
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, 2008, 5141 : 58 - +