An intrusion response decision-making model based on hierarchical task network planning

被引:42
|
作者
Mu, Chengpo [1 ]
Li, Yingjiu [2 ]
机构
[1] Beijing Inst Technol, Key Lab Mech Engn & Control, Beijing 100081, Peoples R China
[2] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
关键词
Automated intrusion response system; Hierarchical task network planning; Intrusion response decision-making; Intrusion detection;
D O I
10.1016/j.eswa.2009.07.079
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An intrusion response decision-making model based on hierarchical task network (HTN) planning is presented in the paper. Compared with other response decision-making models, the response decision-making model consists of not only the response measure decision-making process but also response time decision-making process that is firstly proposed in the paper. The response time decision-making model is able to determine response time for different response HTN subtasks. Owing to the introduction of the response time decision-making, the intrusion response system can apply different response strategies to achieve different response goals set by administrators. The proposed response measure decision-making model can optimize a response plan by balancing the response effectiveness and the response negative impact in both a single response measure and a set of response measures. The response decision-making model is self-adaptive and has the ability of tolerating to false positive IDS alerts. The proposed model has been used in the intrusion detection alert management and intrusion response system (IDAM&IRS) developed by us. The functions and architecture of IDAM&IRS are introduced in this paper. In addition, the intrusion response experiments of IDAM&IRS are presented, and the features of the response decision-making model are summarized. (C) 2009 Elsevier Ltd. All rights reserved.
引用
收藏
页码:2465 / 2472
页数:8
相关论文
共 50 条
  • [1] Resource-constrained Hierarchical Task Network planning under uncontrollable durations for emergency decision-making
    Zhao, Peng
    Qi, Chao
    Liu, Dian
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2017, 33 (06) : 3819 - 3834
  • [2] Hierarchical decision-making model for planning and controlling stochastic projects
    GolenkoGinzburg, D
    Gonik, A
    Kesler, S
    INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 1996, 46 : 39 - 54
  • [3] Intrusion Response Decision-making Method Based on Reinforcement Learning
    Yang, Jun-nan
    Zhang, Hong-qi
    Zhang, Chuan-fu
    2018 INTERNATIONAL CONFERENCE ON COMMUNICATION, NETWORK AND ARTIFICIAL INTELLIGENCE (CNAI 2018), 2018, : 154 - 162
  • [4] The Decision-making Study of the Rural Network Planning Based on the Hierarchical Order Dynamic Gray Relationship
    Li Wei
    Yan Ning
    Zhang Zhengang
    2009 INTERNATIONAL CONFERENCE ON FUTURE BIOMEDICAL INFORMATION ENGINEERING (FBIE 2009), 2009, : 431 - 434
  • [5] Emergency Response Decision-Making based on HTN Planning
    Qi Chao
    Wang Hongwei
    26TH CHINESE CONTROL AND DECISION CONFERENCE (2014 CCDC), 2014, : 3765 - 3770
  • [6] Survey of intrusion response decision-making techniques of automated intrusion response systems
    Mu, Chengpo
    Huang, Houkuan
    Tian, Shengfeng
    Li, Xiangjun
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2008, 45 (08): : 1290 - 1298
  • [7] Adaptive model of decision-making in planning
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (01):
  • [8] PREDICTIVE MODEL OF AN OPERATOR IN A DECISION-MAKING TASK
    PACKER, JS
    PROCEEDINGS OF THE INSTITUTION OF ELECTRICAL ENGINEERS-LONDON, 1972, 119 (01): : 88 - &
  • [9] PREDICTIVE MODEL OF AN OPERATOR IN A DECISION-MAKING TASK
    YOUNG, KJ
    PROCEEDINGS OF THE INSTITUTION OF ELECTRICAL ENGINEERS-LONDON, 1972, 119 (05): : 628 - &
  • [10] Decision-making method of highway network planning based on prospect theory
    Li Xiaowei
    INTELLIGENT AND INTEGRATED SUSTAINABLE MULTIMODAL TRANSPORTATION SYSTEMS PROCEEDINGS FROM THE 13TH COTA INTERNATIONAL CONFERENCE OF TRANSPORTATION PROFESSIONALS (CICTP2013), 2013, 96 : 2042 - 2050