Automated reaction based on risk analysis and attackers skills in intrusion detection systems - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2008

Automated reaction based on risk analysis and attackers skills in intrusion detection systems

Résumé

Nowadays, intrusion detection systems do not only aim to detect attacks; but they go beyond by providing reaction mechanisms to cope with detected attacks, or at least reduce their effects. Previous research works have proposed several methods to automatically select possible countermeasures capable of ending the detected attack, but without taking into account their side effects. In fact, countermeasures can be as harmful as the detected attack. Moreover, sometimes selected countermeasures are not adapted to the attacker’s actions and/or knowledge. In this paper, we propose to turn the reaction selection process intelligent by giving means to (i) quantify the effectiveness and select the countermeasure that has the minimum negative side effect on the information system by adopting a risk assessment and analysis approach, and (ii) assess the skill and knowledge level of the attacker from a defensive point of view.
Fichier principal
Vignette du fichier
latex8.pdf (372.28 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00540864 , version 1 (29-11-2010)

Identifiants

Citer

Wael Kanoun, Nora Cuppens-Bouhlahia, Frédéric Cuppens, José Araujo. Automated reaction based on risk analysis and attackers skills in intrusion detection systems. CRISIS'08: 3rd International Conference on Risks and Security of Internet and Systems, Oct 2008, Tozeur, Tunisia. pp.117 - 124, ⟨10.1109/CRISIS.2008.4757471⟩. ⟨hal-00540864⟩
92 Consultations
580 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More