DocumentCode
1242281
Title
A Game Theoretical Framework on Intrusion Detection in Heterogeneous Networks
Author
Chen, Lin ; Leneutre, Jean
Author_Institution
Dept. of Comput. Sci. & Networks, Telecom ParisTech, Paris
Volume
4
Issue
2
fYear
2009
fDate
6/1/2009 12:00:00 AM
Firstpage
165
Lastpage
178
Abstract
Due to the dynamic, distributed, and heterogeneous nature of today´s networks, intrusion detection systems (IDSs) have become a necessary addition to the security infrastructure and are widely deployed as a complementary line of defense to classical security approaches. In this paper, we address the intrusion detection problem in heterogeneous networks consisting of nodes with different noncorrelated security assets. In our study, two crucial questions are: What are the expected behaviors of rational attackers? What is the optimal strategy of the defenders (IDSs)? We answer the questions by formulating the network intrusion detection as a noncooperative game and performing an in-depth analysis on the Nash equilibrium and the engineering implications behind. Based on our game theoretical analysis, we derive the expected behaviors of rational attackers, the minimum monitor resource requirement, and the optimal strategy of the defenders. We then provide guidelines for IDS design and deployment. We also show how our game theoretical framework can be applied to configure the intrusion detection strategies in realistic scenarios via a case study. Finally, we evaluate the proposed game theoretical framework via simulations. The simulation results show both the correctness of the analytical results and the effectiveness of the proposed guidelines.
Keywords
game theory; security of data; Nash equilibrium; game theoretical analysis; heterogeneous networks; intrusion detection systems; noncooperative game; optimal strategy; security infrastructure; Game theory; Nash equilibrium (NE); intrusion detection system (IDS);
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2009.2019154
Filename
4815406
Link To Document