Fuzzy Online Risk Assessment for Distributed Intrusion Prediction and Prevention Systems

被引:13
|
作者
Haslum, Kjetil [1 ]
Abraham, Ajith [1 ]
Knapskog, Svein [1 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Quantifiable Qual Serv Commun Syst, N-7491 Trondheim, Norway
关键词
D O I
10.1109/UKSIM.2008.30
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A Distributed Intrusion Prediction and Prevention Systems (DIPPS) not only detects and prevents possible intrusions but also possesses the capability to predict possible intrusions in a distributed network. Based on the DIPS sensors, instead of merely preventing the attackers or blocking traffic, we propose a fuzzy logic based online risk assessment scheme. The key idea of DIPPS is to protect the network(s) linked to assets, which are considered to be very risky. To implement DIPPS we used a Distributed Intrusion Detection System (DIDS) with extended real time traffic surveillance and online risk assessment. To model and predict the next step of an attacker, we used a Hidden Markov Model (HMM) that captures the interaction between the attacker and the network. The interaction between various DIDS and integration of their output are achieved through a HMM. The novelty of this paper is the detailed development of Fuzzy Logic Controllers to estimate the various risk(s) that are dependent on several other variables based on the inputs from HMM modules and the DIDS agents. To develop the fuzzy risk expert system, if-then fuzzy rules were formulated based on interviews with security experts and network administrators. Preliminary results indicate that such a system is very practical for protecting assets which are prone to attacks or misuse, i.e. highly at risk.
引用
收藏
页码:216 / 223
页数:8
相关论文
共 50 条
  • [31] Tangibility of Fuzzy Approach Risk Assessment in Distributed Software Development Projects
    Birant, Kokten Ulas
    Isik, Ali Hakan
    Batar, Mustafa
    ARTIFICIAL INTELLIGENCE AND APPLIED MATHEMATICS IN ENGINEERING PROBLEMS, 2020, 43 : 676 - 683
  • [32] Predicting the Risk of Newborns Based on Fuzzy Clustering Method with Prediction Risk Assessment
    Thomas, Jyothi
    Kulanthaivel, G.
    2014 INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING AND INFORMATICS (IC3I), 2014, : 38 - 42
  • [33] Fuzzy inference to risk assessment on nuclear engineering systems
    Ferreira Guimaraes, Antonio Cesar
    Franklin Lapa, Celso Marcelo
    APPLIED SOFT COMPUTING, 2007, 7 (01) : 17 - 28
  • [34] Pipeline Risk Assessment Using a Fuzzy Systems Network
    Perez Hoyos, Gustavo
    PROCEEDINGS OF THE 2013 JOINT IFSA WORLD CONGRESS AND NAFIPS ANNUAL MEETING (IFSA/NAFIPS), 2013, : 1495 - 1498
  • [35] Credit Risk Assessment of Online Shops Based on Fuzzy Consistent Matrix
    Yao, Yao
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2011, 5 (02): : 163 - 169
  • [36] Vulnerability assessment of android instant messaging application and network intrusion detection prevention systems
    Gaharwar, Ratan Singh
    Gupta, Roopam
    JOURNAL OF STATISTICS & MANAGEMENT SYSTEMS, 2020, 23 (02): : 399 - 406
  • [37] Quantitative intrusion intensity assessment for intrusion detection systems
    Kim, Dong Seong
    Lee, Sang Min
    Kim, Tae Hwan
    Park, Jong Sou
    SECURITY AND COMMUNICATION NETWORKS, 2012, 5 (10) : 1199 - 1208
  • [38] Online Intrusion Detection for Internet of Things Systems With Full Bayesian Possibilistic Clustering and Ensembled Fuzzy Classifiers
    Li, Fang-Qi
    Zhao, Rui-Jie
    Wang, Shi-Lin
    Chen, Li-Bo
    Liew, Alan Wee-Chung
    Ding, Weiping
    IEEE TRANSACTIONS ON FUZZY SYSTEMS, 2022, 30 (11) : 4605 - 4617
  • [39] Fuzzy-grey prediction based dynamic failure detector for distributed systems
    Tian, Dong
    Chen, Shuyu
    Mao, Taiping
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PROCEEDINGS, 2007, 4494 : 131 - +
  • [40] DEVS simulation of distributed intrusion detection systems
    Cho, TH
    Kim, HJ
    SIMULATION-TRANSACTIONS OF THE SOCIETY FOR MODELING AND SIMULATION INTERNATIONAL, 2001, 18 (03): : 133 - 146