首页> 外文会议>International conference on autonomic computing and communications >Threat-Model-Driven Runtime Adaptation and Evaluation of Intrusion Detection System
【24h】

Threat-Model-Driven Runtime Adaptation and Evaluation of Intrusion Detection System

机译:威胁模型驱动的运行时适应与入侵检测系统的评估

获取原文

摘要

We present a mechanism for autonomous self-adaptation of a network-based intrusion detection system (IDS). The system is composed of a set of cooperating agents, each of which is based on an existing network behavior analysis method. The self adaptation mechanism is based on the insertion of a small number of challenges, i.e. known instances of past legitimate or malicious behavior. The response of individual system components to these challenges is used to measure and eventually optimize the system performance in terms of accuracy. In this work we show how to choose the challenges in a way such that the IDS attaches more importance to the detection of attacks that cause much damage.
机译:我们提出了一种基于网络的入侵检测系统(ID)的自主自适应的机制。该系统由一组协作代理组成,每个协作代理基于现有的网络行为分析方法。自适应机制基于插入少量挑战,即过去合法或恶意行为的已知实例。各个系统组件对这些挑战的响应用于测量并最终在准确性方面优化系统性能。在这项工作中,我们展示了如何选择挑战,使IDS更重视检测导致损坏的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号