DocumentCode
501676
Title
A Framework for Cost Sensitive Assessment of Intrusion Response Selection
Author
Strasburg, Chris ; Stakhanova, Natalia ; Basu, Samik ; Wong, Johnny S.
Author_Institution
Dept. of Comput. Sci., Iowa State Univ., Ames, IA, USA
Volume
1
fYear
2009
fDate
20-24 July 2009
Firstpage
355
Lastpage
360
Abstract
In recent years, cost-sensitive intrusion response has gained significant interest, mainly due to its emphasis on the balance between potential damage incurred by the intrusion and cost of the response. However, one of the challenges in applying this approach is defining a consistent and adaptable measurement of these cost factors on the basis of system requirements and policy. In this paper,we present a host-based framework for the cost-sensitive assessment and selection of intrusion response. Specifically,we introduce a set of measurements that characterize the potential costs associated with the intrusion handling process, and propose an intrusion response evaluation method with respect to the risk of potential intrusion damage, the effectiveness of the response action and the response cost for a system. We provide an implementation of the proposed solution as an IDS-independent plugin tool and demonstrate its advantages on the several attack examples.
Keywords
security of data; cost sensitive assessment; cost sensitive intrusion response; host based framework; intrusion handling process; intrusion response evaluation; intrusion response selection; potential intrusion damage; system policy; system requirements; Application software; Computer applications; Computer science; Computer security; Context modeling; Cost function; Intrusion detection; Privacy; Protection; USA Councils; Performance; Security and Privacy Protection; Security and Protection; User/Machine Systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
Conference_Location
Seattle, WA
ISSN
0730-3157
Print_ISBN
978-0-7695-3726-9
Type
conf
DOI
10.1109/COMPSAC.2009.54
Filename
5254241
Link To Document