首页> 外文会议>International Conference on Innovations in Bio-Inspired Computing and Applications >Modeling an Anomaly-Based Intrusion Prevention System Using Game Theory
【24h】

Modeling an Anomaly-Based Intrusion Prevention System Using Game Theory

机译:使用博弈论模拟基于异常的入侵防御系统

获取原文

摘要

In Cloud Computing environment, the availability, authentication and integrity became a more challenging problem. Indeed, the classical solutions of security based on intrusion detection system and firewalls are easily bypassed by experienced attackers. In addition, the use of different technologies in term of security didn't mitigate the attack considerably. To achieve network system's security with the complexity and the diversity of attack types is too difficult and costly. However, to make them more resistant to attacks, anomaly-based Intrusion Prevention System (IPS) are used. Such systems take into consideration the probability of legitimacy of a packet if it didn't match any signature of malicious packets. In this paper, a competitive normal form game is developed based on the probability of packets' legitimacy and the trust that an IPS has over the owner of the packet. Furthermore, a decision is made about dropping, accepting or testing packet in the network, and different Nash Equilibriums are calculated based on the system's parameters. Our approach demonstrated its feasibility in term of prediction of the cases in which the system could be compromised and the actions that should be performed in case of an intrusion.
机译:在云计算环境中,可用性,身份验证和完整性成为一个更具挑战性的问题。实际上,经验丰富的攻击者很容易绕过基于入侵检测系统和防火墙的安全性的经典解。此外,在安全性期间使用不同的技术并没有大大减轻攻击。为了实现网络系统的安全性,复杂性和攻击类型的多样性太难且昂贵。但是,为了使它们更耐攻击,使用基于异常的入侵防御系统(IP)。如果它不符合恶意数据包的任何签名,则此类系统考虑到数据包的合法性概率。在本文中,基于数据包合法性的概率和IPS对数据包所有者的信任来开发竞争正常形式游戏。此外,关于网络中的丢弃,接受或测试数据包进行决定,并且基于系统的参数计算不同的纳什均衡。我们的方法在预测系统可能受到损害的情况下证明其可行性以及在入侵时应进行的动作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号