Online risk assessment of intrusion scenarios using D-S evidence theory

C. P. Mu, X. J. Li, H. K. Huang, S. F. Tian

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

31 Citations (Scopus)

Abstract

In the paper, an online risk assessment model based on D-S evidence theory is presented. The model can quantitate the risk caused by an intrusion scenario in real time and provide an objective evaluation of the target security state. The results of the online risk assessment show a clear and concise picture of both the intrusion progress and the target security state. The model makes full use of available information from both IDS alerts and protected targets. As a result, it can deal with uncertainties and subjectiveness very well in its evaluation process. In IDAM&IRS, the model serves as the foundation for intrusion response decision-making.

Original languageEnglish
Title of host publicationComputer Security - ESORICS 2008 - 13th European Symposium on Research in Computer Security, Proceedings
PublisherSpringer Verlag
Pages35-48
Number of pages14
ISBN (Print)3540883126, 9783540883128
DOIs
Publication statusPublished - 2008
Event13th European Symposium on Research in Computer Security, ESORICS 2008 - Malaga, Spain
Duration: 6 Oct 20088 Oct 2008

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5283 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference13th European Symposium on Research in Computer Security, ESORICS 2008
Country/TerritorySpain
CityMalaga
Period6/10/088/10/08

Keywords

  • Alert processing
  • D-S evidence theory
  • Intrusion detection
  • Intrusion response
  • Online risk assessment

Fingerprint

Dive into the research topics of 'Online risk assessment of intrusion scenarios using D-S evidence theory'. Together they form a unique fingerprint.

Cite this