DocumentCode :
1340519
Title :
Maintaining Defender´s Reputation in Anomaly Detection Against Insider Attacks
Author :
Zhang, Nan ; Yu, Wei ; Fu, Xinwen ; Das, Sajal K.
Author_Institution :
Dept. of Comput. Sci., George Washington Univ., Washington, DC, USA
Volume :
40
Issue :
3
fYear :
2010
fDate :
6/1/2010 12:00:00 AM
Firstpage :
597
Lastpage :
611
Abstract :
We address issues related to establishing a defender´s reputation in anomaly detection against two types of attackers: 1) smart insiders, who learn from historic attacks and adapt their strategies to avoid detection/punishment, and 2) nai??ve attackers, who blindly launch their attacks without knowledge of the history. In this paper, we propose two novel algorithms for reputation establishment-one for systems solely consisting of smart insiders and the other for systems in which both smart insiders and nai??ve attackers are present. The theoretical analysis and performance evaluation show that our reputation-establishment algorithms can significantly improve the performance of anomaly detection against insider attacks in terms of the tradeoff between detection and false positives.
Keywords :
security of data; anomaly detection; defender reputation; insider attacks; nai??ve attackers; reputation-establishment algorithms; smart insiders; Anomaly detection; game theory; insider attack; Algorithms; Computer Security; Decision Support Techniques; Fraud; Game Theory; Models, Theoretical;
fLanguage :
English
Journal_Title :
Systems, Man, and Cybernetics, Part B: Cybernetics, IEEE Transactions on
Publisher :
ieee
ISSN :
1083-4419
Type :
jour
DOI :
10.1109/TSMCB.2009.2033564
Filename :
5340523
Link To Document :
بازگشت