• DocumentCode
    3081162
  • Title

    Optimal Bayesian network design for efficient Intrusion Detection

  • Author

    Ruiz-Agundez, Igor ; Penya, Yoseba K. ; Bringas, Pablo Garcia

  • Author_Institution
    DeustoTech, Univ. of Deusto, Bilbao, Spain
  • fYear
    2010
  • fDate
    13-15 May 2010
  • Firstpage
    444
  • Lastpage
    451
  • Abstract
    Computer networks are nowadays subject to an increasing number of attacks. Intrusion Detection Systems (IDS) are designed to protect them by identifying malicious behaviours or improper uses. Since the scope is different in each case (register already-known menaces to later recognise them or model legitimate uses to trigger when a variation is detected), IDS have failed so far to respond against both kind of attacks. Lately, Bayesian networks (BN) have provided an innovative solution to fill this gap by integrating both domains within a common knowledge representation model. Still, the huge computational effort that has to be invested in the BN with such knowledge model makes them not feasible and not practical for real-world scenarios. Against this background, we propose the use of expert knowledge to enhance and optimise the design of the IDS, shortening subsequently the training process. This expert knowledge is represented as a set of hypotheses that must be verified to justify their utility. In this way, we have tested our approach with several samples of data showing that all the hypotheses assumed were true and, therefore, that the proposed methodology to trim down the design and training processes yields an optimal Bayesian network for Intrusion Detection.
  • Keywords
    authorisation; belief networks; computer network security; expert systems; training; Bayesian network design; computer network attacks; expert knowledge; hypotheses; intrusion detection systems; knowledge representation model; malicious behaviours; training process; Bayesian methods; Computer networks; Computer security; IP networks; Intrusion detection; Knowledge representation; Process design; Protection; Registers; Testing; Artificial intelligence; Bayesian networks; Cyber security; Intrusion Detection Systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Human System Interactions (HSI), 2010 3rd Conference on
  • Conference_Location
    Rzeszow
  • Print_ISBN
    978-1-4244-7560-5
  • Type

    conf

  • DOI
    10.1109/HSI.2010.5514530
  • Filename
    5514530