• DocumentCode
    1135259
  • Title

    Inference of Security Hazards from Event Composition Based on Incomplete or Uncertain Information

  • Author

    Wasserkrug, Segev ; Gal, Avigdor ; Etzion, Opher

  • Author_Institution
    IBM Haifa Resarch Lab., Technion Israel Inst. of Technol., Haifa
  • Volume
    20
  • Issue
    8
  • fYear
    2008
  • Firstpage
    1111
  • Lastpage
    1114
  • Abstract
    In many security-related contexts, a quick recognition of security hazards is required. Such recognition is challenging, since available information sources are often insufficient to infer the occurrence of hazards with certainty. This requires that the recognition of security hazard is carried out using inference based on patterns of occurrences distributed over space and time. The two main existing approaches to the inference of security hazards are a) custom-coded solutions, which are tailored to specific patterns, and cannot respond quickly to changes in the patterns of occurrences used for inference, and b) approaches based on direct statistical inferencing techniques, such as regression, which do not enable combining various kinds of evidence regarding the same hazard. In this work, we introduce a more generic formal framework which overcomes the aforementioned deficiencies, together with a case study illustrating the detection of DoS attacks.
  • Keywords
    inference mechanisms; security of data; statistical analysis; uncertainty handling; direct statistical inferencing technique; event composition; formal framework; incomplete information; security hazard; uncertain information; uncertainty handling; Decision support; Fuzzy and probabilistic reasoning; Network-level security and protection; Uncertainty;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2008.74
  • Filename
    4492778