Advanced reaction using risk assessment in intrusion detection systems - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2007

Advanced reaction using risk assessment in intrusion detection systems

Résumé

Current intrusion detection systems go beyond the detection of attacks and provide reaction mechanisms to cope with detected attacks or at least reduce their effect. Previous research works have proposed methods to automatically select possible countermeasures capable of ending the detected attack. But actually, countermeasures have side effects and can be as harmful as the detected attack. In this paper, we propose to improve the reaction selection process by giving means to quantify the effectiveness and select the countermeasure that has the minimum negative side effect on the information system. To achieve this goal, we adopt a risk assessment and analysis approach.
Fichier principal
Vignette du fichier
Article.pdf (356.66 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00540863 , version 1 (29-11-2010)

Identifiants

  • HAL Id : hal-00540863 , version 1

Citer

Wael Kanoun, Nora Cuppens-Bouhlahia, Frédéric Cuppens, Fabien Autrel. Advanced reaction using risk assessment in intrusion detection systems. CRITIS'07: 2nd international workshop on Critical Information Infrastructures Security, Oct 2007, Malaga, Spain. ⟨hal-00540863⟩
82 Consultations
188 Téléchargements

Partager

Gmail Facebook X LinkedIn More