TY - JOUR
T1 - An intrusion response decision-making model based on hierarchical task network planning
AU - Mu, Chengpo
AU - Li, Yingjiu
PY - 2010/3/15
Y1 - 2010/3/15
N2 - An intrusion response decision-making model based on hierarchical task network (HTN) planning is presented in the paper. Compared with other response decision-making models, the response decision-making model consists of not only the response measure decision-making process but also response time decision-making process that is firstly proposed in the paper. The response time decision-making model is able to determine response time for different response HTN subtasks. Owing to the introduction of the response time decision-making, the intrusion response system can apply different response strategies to achieve different response goals set by administrators. The proposed response measure decision-making model can optimize a response plan by balancing the response effectiveness and the response negative impact in both a single response measure and a set of response measures. The response decision-making model is self-adaptive and has the ability of tolerating to false positive IDS alerts. The proposed model has been used in the intrusion detection alert management and intrusion response system (IDAM&IRS) developed by us. The functions and architecture of IDAM&IRS are introduced in this paper. In addition, the intrusion response experiments of IDAM&IRS are presented, and the features of the response decision-making model are summarized.
AB - An intrusion response decision-making model based on hierarchical task network (HTN) planning is presented in the paper. Compared with other response decision-making models, the response decision-making model consists of not only the response measure decision-making process but also response time decision-making process that is firstly proposed in the paper. The response time decision-making model is able to determine response time for different response HTN subtasks. Owing to the introduction of the response time decision-making, the intrusion response system can apply different response strategies to achieve different response goals set by administrators. The proposed response measure decision-making model can optimize a response plan by balancing the response effectiveness and the response negative impact in both a single response measure and a set of response measures. The response decision-making model is self-adaptive and has the ability of tolerating to false positive IDS alerts. The proposed model has been used in the intrusion detection alert management and intrusion response system (IDAM&IRS) developed by us. The functions and architecture of IDAM&IRS are introduced in this paper. In addition, the intrusion response experiments of IDAM&IRS are presented, and the features of the response decision-making model are summarized.
KW - Automated intrusion response system
KW - Hierarchical task network planning
KW - Intrusion detection
KW - Intrusion response decision-making
UR - http://www.scopus.com/inward/record.url?scp=70449517238&partnerID=8YFLogxK
U2 - 10.1016/j.eswa.2009.07.079
DO - 10.1016/j.eswa.2009.07.079
M3 - Article
AN - SCOPUS:70449517238
SN - 0957-4174
VL - 37
SP - 2465
EP - 2472
JO - Expert Systems with Applications
JF - Expert Systems with Applications
IS - 3
ER -