Fuzzy Online Risk Assessment for Distributed Intrusion Prediction and Prevention Systems

被引:13
|
作者
Haslum, Kjetil [1 ]
Abraham, Ajith [1 ]
Knapskog, Svein [1 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Quantifiable Qual Serv Commun Syst, N-7491 Trondheim, Norway
关键词
D O I
10.1109/UKSIM.2008.30
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A Distributed Intrusion Prediction and Prevention Systems (DIPPS) not only detects and prevents possible intrusions but also possesses the capability to predict possible intrusions in a distributed network. Based on the DIPS sensors, instead of merely preventing the attackers or blocking traffic, we propose a fuzzy logic based online risk assessment scheme. The key idea of DIPPS is to protect the network(s) linked to assets, which are considered to be very risky. To implement DIPPS we used a Distributed Intrusion Detection System (DIDS) with extended real time traffic surveillance and online risk assessment. To model and predict the next step of an attacker, we used a Hidden Markov Model (HMM) that captures the interaction between the attacker and the network. The interaction between various DIDS and integration of their output are achieved through a HMM. The novelty of this paper is the detailed development of Fuzzy Logic Controllers to estimate the various risk(s) that are dependent on several other variables based on the inputs from HMM modules and the DIDS agents. To develop the fuzzy risk expert system, if-then fuzzy rules were formulated based on interviews with security experts and network administrators. Preliminary results indicate that such a system is very practical for protecting assets which are prone to attacks or misuse, i.e. highly at risk.
引用
收藏
页码:216 / 223
页数:8
相关论文
共 50 条
  • [41] Information sharing for distributed intrusion detection systems
    Peng, Tao
    Leckie, Christopher
    Ramamohanarao, Kotagiri
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2007, 30 (03) : 877 - 899
  • [42] DEVS simulation of distributed intrusion detection systems
    Cho, Tae Ho
    Kim, Hyung Jong
    Transactions of the Society for Computer Simulation, 2002, 18 (03): : 133 - 146
  • [43] Intrusion ripple analysis in distributed information systems
    Yau, SS
    Zhu, J
    PROCEEDINGS OF THE SIXTH IEEE COMPUTER SOCIETY WORKSHOP ON FUTURE TRENDS OF DISTRIBUTED COMPUTING SYSTEMS, 1997, : 28 - 33
  • [44] Online distributed fuzzy modeling of nonlinear PDE systems: Computation based on adaptive algorithms
    Mardani, Mohammad Mehdi
    Shasadeghi, Mokhtar
    Safarinejadian, Behrouz
    Dragicevic, Tomislav
    APPLIED SOFT COMPUTING, 2019, 77 : 76 - 87
  • [46] Dynamic authorization and intrusion response in distributed systems
    Ryutov, T
    Neuman, C
    Kim, D
    DARPA INFORMATION SURVIVABILITY CONFERENCE AND EXPOSITION, VOL I, PROCEEDINGS, 2003, : 50 - 61
  • [47] FID: Fuzzy Based Intrusion Detection for Distributed Smart Devices
    Hendaoui, Fatma
    Eltaief, Hamdi
    Youssef, Habib
    2017 IEEE/ACS 14TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2017, : 1330 - 1337
  • [48] GP ensemble for distributed intrusion detection systems
    Folino, G
    Pizzuti, C
    Spezzano, G
    PATTERN RECOGNITION AND DATA MINING, PT 1, PROCEEDINGS, 2005, 3686 : 54 - 62
  • [49] Agent-based IDMEF Alerting Infrastructure for Distributed Intrusion Detection and Prevention Systems: Design and Validation
    Lupu, Radu
    Badea, Radu
    Mihai, Ion Cosmin
    2016 INTERNATIONAL CONFERENCE ON COMMUNICATIONS (COMM 2016), 2016, : 281 - 284
  • [50] Towards Cyber Defense: Research in Intrusion Detection and Intrusion Prevention Systems
    Faysel, Mohammad A.
    Haque, Syed S.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (07): : 316 - 325