Fuzzy Online Risk Assessment for Distributed Intrusion Prediction and Prevention Systems

被引:13
|
作者
Haslum, Kjetil [1 ]
Abraham, Ajith [1 ]
Knapskog, Svein [1 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Quantifiable Qual Serv Commun Syst, N-7491 Trondheim, Norway
关键词
D O I
10.1109/UKSIM.2008.30
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A Distributed Intrusion Prediction and Prevention Systems (DIPPS) not only detects and prevents possible intrusions but also possesses the capability to predict possible intrusions in a distributed network. Based on the DIPS sensors, instead of merely preventing the attackers or blocking traffic, we propose a fuzzy logic based online risk assessment scheme. The key idea of DIPPS is to protect the network(s) linked to assets, which are considered to be very risky. To implement DIPPS we used a Distributed Intrusion Detection System (DIDS) with extended real time traffic surveillance and online risk assessment. To model and predict the next step of an attacker, we used a Hidden Markov Model (HMM) that captures the interaction between the attacker and the network. The interaction between various DIDS and integration of their output are achieved through a HMM. The novelty of this paper is the detailed development of Fuzzy Logic Controllers to estimate the various risk(s) that are dependent on several other variables based on the inputs from HMM modules and the DIDS agents. To develop the fuzzy risk expert system, if-then fuzzy rules were formulated based on interviews with security experts and network administrators. Preliminary results indicate that such a system is very practical for protecting assets which are prone to attacks or misuse, i.e. highly at risk.
引用
收藏
页码:216 / 223
页数:8
相关论文
共 50 条
  • [21] Intrusion prevention systems: superior security
    Rowan, Tom
    Network Security, 2007, 2007 (09) : 11 - 15
  • [22] Evaluating intrusion prevention systems with evasions
    Sarela, Mikko
    Kyostila, Tomi
    Kiravuo, Timo
    Manner, Jukka
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (16)
  • [23] A survey of intrusion detection and prevention systems
    Patel A.
    Qassim Q.
    Wills C.
    Information Management and Computer Security, 2010, 18 (04): : 277 - 290
  • [24] A Survey of Intrusion Detection and Prevention Systems
    Erney, Tristan
    Chowdhury, Md Minhaz
    2022 IEEE WORLD AI IOT CONGRESS (AIIOT), 2022, : 578 - 584
  • [25] Building dependable Intrusion Prevention Systems
    Botwicz, Jakub
    Buciak, Piotr
    Sapiecha, Piotr
    DEPCOS-RELCOMEX 2006, 2006, : 135 - +
  • [26] A Novel Online Incremental Learning Intrusion Prevention System
    Constantinides, Christos
    Shiaeles, Stavros
    Ghita, Bogdan
    Kolokotronis, Nicholas
    2019 10TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2019,
  • [27] A Real-Time Risk Assessment Model for Intrusion Detection Systems
    Chakir, El Mostapha
    Moughit, Mohamed
    Idrissi Khamlichi, Youness
    2017 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC), 2017,
  • [28] The Design and Implementation of Seawater Intrusion Risk Assessment Geographic Information Systems
    Chen, Guangquan
    Xu, Xingyong
    Yu, Hongjun
    Su, Qiao
    Cao, Jianrong
    PROCEEDINGS OF THE FIRST SYMPOSIUM ON DISASTER RISK ANALYSIS AND MANAGEMENT IN CHINESE LITTORAL REGIONS, 2011, 18 : 96 - 102
  • [29] Online Risk Assessment of Intrusion Scenarios Using D-S Evidence Theory
    Mu, C. P.
    Li, X. J.
    Huang, H. K.
    Tian, S. F.
    COMPUTER SECURITY - ESORIC 2008, PROCEEDINGS, 2008, 5283 : 35 - +
  • [30] Intelligent Automated Intrusion Response System based on Fuzzy Decision Making and Risk Assessment
    Berenjian, Samaneh
    Shajari, Mehdi
    Farshid, Nadieh
    Hatamian, Majid
    2016 IEEE 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS (IS), 2016, : 709 - 714