Decision on optimal active response based on intrusion graph

He Hu*, Chang Zhen Hu, Shu Ping Yao

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

1 Citation (Scopus)

Abstract

To help network administrators to pre-identify potential vulnerabilities and security threats, an active response strategy selecting method based on attack graph was presented. In this method, the network attack graph model forecast aggressive behavior, and analysed attack path with quantitative metrics. The method used the observations during the attack process to match attack graph and updates the belief state. Finally, the partial observable Markov game (POMG) algorithm was used to choose optimal active response strategy. Experimental results show that the active response strategy selection method based on attack graph can improve the accuracy and effectiveness of the response.

Original languageEnglish
Pages (from-to)1659-1664
Number of pages6
JournalBeijing Gongye Daxue Xuebao / Journal of Beijing University of Technology
Volume38
Issue number11
Publication statusPublished - Nov 2012

Keywords

  • Intrusion graph
  • Network security
  • Partial observable Markov game (POMG)

Fingerprint

Dive into the research topics of 'Decision on optimal active response based on intrusion graph'. Together they form a unique fingerprint.

Cite this