首页> 外文会议>Conference on Data Mining, Intrusion Detection, Information Assurance, and Data Networks Security >Selection of intrusion detection system threshold bounds for effective sensor fusion
【24h】

Selection of intrusion detection system threshold bounds for effective sensor fusion

机译:选择入侵检测系统阈值边界以实现有效的传感器融合

获取原文

摘要

The motivation behind the fusion of Intrusion Detection Systems was the realization that with the increasing traffic and increasing complexity of attacks, none of the present day stand-alone Intrusion Detection Systems can meet the high demand for a very high detection rate and an extremely low false positive rate. Multi-sensor fusion can be used to meet these requirements by a refinement of the combined response of different Intrusion Detection Systems. In this paper, we show the design technique of sensor fusion to best utilize the useful response from multiple sensors by an appropriate adjustment of the fusion threshold. The threshold is generally chosen according to the past experiences or by an expert system. In this paper, we show that the choice of the threshold bounds according to the Chebyshev inequality principle performs better. This approach also helps to solve the problem of scalability and has the advantage of failsafe capability. This paper theoretically models the fusion of Intrusion Detection Systems for the purpose of proving the improvement in performance, supplemented with the empirical evaluation. The combination of complementary sensors is shown to detect more attacks than the individual components. Since the individual sensors chosen detect sufficiently different attacks, their result can be merged for improved performance. The combination is done in different ways like (i) taking all the alarms from each system and avoiding duplications, (ii) taking alarms from each system by fixing threshold bounds, and (iii) rule-based fusion with a priori knowledge of the individual sensor performance. A number of evaluation metrics are used, and the results indicate that there is an overall enhancement in the performance of the combined detector using sensor fusion incorporating the threshold bounds and significantly better performance using simple rule-based fusion.
机译:融合入侵检测系统背后的动机是认识到,随着流量的增加和攻击的复杂性的增加,当今的独立入侵检测系统都无法满足对非常高的检测率和极低的虚假率的高要求。阳性率。通过优化不同入侵检测系统的组合响应,可以使用多传感器融合来满足这些要求。在本文中,我们展示了传感器融合的设计技术,可以通过适当调整融合阈值来最佳利用来自多个传感器的有用响应。通常根据过去的经验或由专家系统选择阈值。在本文中,我们证明了根据切比雪夫不等式原理选择阈值边界的效果更好。此方法还有助于解决可伸缩性问题,并具有故障保护功能的优点。本文从理论上对入侵检测系统的融合进行建模,以证明其性能有所提高,并辅以实证评估。互补传感器的组合显示出比单个组件检测到更多的攻击。由于选择的各个传感器检测到足够不同的攻击,因此可以合并其结果以提高性能。组合以不同的方式完成,例如(i)从每个系统获取所有警报并避免重复;(ii)通过固定阈值边界从每个系统获取警报;以及(iii)基于规则的融合并具有个人的先验知识传感器性能。使用了许多评估指标,结果表明,使用结合了阈值边界的传感器融合,组合检测器的性能得到了总体增强,而使用基于简单规则的融合,则性能显着提高。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号