首页> 外文会议> >Adaptation techniques for intrusion detection and intrusion response systems
【24h】

Adaptation techniques for intrusion detection and intrusion response systems

机译:入侵检测和入侵响应系统的自适应技术

获取原文

摘要

The paper examines techniques for providing adaptation in intrusion detection and intrusion response systems. As attacks on computer systems are becoming increasingly numerous and sophisticated, there is a growing need for intrusion detection and response systems to dynamically adapt to better detect and respond to attacks. The Adaptive Hierarchical Agent-based Intrusion Detection System (AHA! IDS) provides detection adaptation by adjusting the amount of system resources devoted to the task of detecting intrusive activities. This is accomplished by dynamically invoking new combinations of lower level detection agents in response to changing circumstances and by adjusting the confidence associated with these lower-level agents. The Adaptive Agent-based Intrusion Response System (AAIRS) provides response adaptation by weighting those responses that have been successful in the past over those techniques that have not been as successful. As a result, the more successful responses are used more often than the less successful techniques. It also adapts responses based on the system's belief that intrusion detection reports are valid. Intuitively, adaptive detection and response systems will provide more robust protection than static, non-adaptive systems.
机译:本文研究了在入侵检测和入侵响应系统中提供适应性的技术。随着对计算机系统的攻击变得越来越多和越来越复杂,对入侵检测和响应系统的需求也日益增长,它们需要动态地适应于更好地检测和响应攻击。基于自适应分层代理的入侵检测系统(AHA!IDS)通过调整专用于检测入侵活动的系统资源的数量来提供检测适应性。这是通过响应不断变化的环境动态调用低级检测代理的新组合并通过调整与这些低级代理相关的置信度来实现的。基于自适应代理的入侵响应系统(AAIRS)通过对过去已经成功的响应进行加权,而不是对那些尚未成功的技术进行加权,从而提供响应适应。结果,与不太成功的技术相比,更成功的响应被更多地使用。它还根据系统认为入侵检测报告有效的信念来调整响应。直观上,自适应检测和响应系统将比静态,非自适应系统提供更强大的保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号