• DocumentCode
    501676
  • Title

    A Framework for Cost Sensitive Assessment of Intrusion Response Selection

  • Author

    Strasburg, Chris ; Stakhanova, Natalia ; Basu, Samik ; Wong, Johnny S.

  • Author_Institution
    Dept. of Comput. Sci., Iowa State Univ., Ames, IA, USA
  • Volume
    1
  • fYear
    2009
  • fDate
    20-24 July 2009
  • Firstpage
    355
  • Lastpage
    360
  • Abstract
    In recent years, cost-sensitive intrusion response has gained significant interest, mainly due to its emphasis on the balance between potential damage incurred by the intrusion and cost of the response. However, one of the challenges in applying this approach is defining a consistent and adaptable measurement of these cost factors on the basis of system requirements and policy. In this paper,we present a host-based framework for the cost-sensitive assessment and selection of intrusion response. Specifically,we introduce a set of measurements that characterize the potential costs associated with the intrusion handling process, and propose an intrusion response evaluation method with respect to the risk of potential intrusion damage, the effectiveness of the response action and the response cost for a system. We provide an implementation of the proposed solution as an IDS-independent plugin tool and demonstrate its advantages on the several attack examples.
  • Keywords
    security of data; cost sensitive assessment; cost sensitive intrusion response; host based framework; intrusion handling process; intrusion response evaluation; intrusion response selection; potential intrusion damage; system policy; system requirements; Application software; Computer applications; Computer science; Computer security; Context modeling; Cost function; Intrusion detection; Privacy; Protection; USA Councils; Performance; Security and Privacy Protection; Security and Protection; User/Machine Systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
  • Conference_Location
    Seattle, WA
  • ISSN
    0730-3157
  • Print_ISBN
    978-0-7695-3726-9
  • Type

    conf

  • DOI
    10.1109/COMPSAC.2009.54
  • Filename
    5254241