2008
DOI: 10.1007/978-3-540-89173-4_6
|View full text |Cite
|
Sign up to set email alerts
|

Advanced Reaction Using Risk Assessment in Intrusion Detection Systems

Abstract: Current intrusion detection systems go beyond the detection of attacks and provide reaction mechanisms to cope with detected attacks or at least reduce their effect. Previous research works have proposed methods to automatically select possible countermeasures capable of ending the detected attack. But actually, countermeasures have side effects and can be as harmful as the detected attack. In this paper, we propose to improve the reaction selection process by giving means to quantify the effectiveness and sel… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
6
0

Year Published

2008
2008
2023
2023

Publication Types

Select...
4
2
2

Relationship

2
6

Authors

Journals

citations
Cited by 14 publications
(6 citation statements)
references
References 10 publications
0
6
0
Order By: Relevance
“…Therefore, this reaction approach can be refined by combining it with the risk analysis model proposed in [19]. This model is used to evaluate the total risk gravity of the IS once an attack is detected and after simulating the execution of the candidate countermeasure.…”
Section: Risk Assessment Modelmentioning
confidence: 99%
See 1 more Smart Citation
“…Therefore, this reaction approach can be refined by combining it with the risk analysis model proposed in [19]. This model is used to evaluate the total risk gravity of the IS once an attack is detected and after simulating the execution of the candidate countermeasure.…”
Section: Risk Assessment Modelmentioning
confidence: 99%
“…Each scenario risk gravity depends on its potentiality and impact factors. Interested readers can refer to [19] for more details.…”
Section: Risk Assessment Modelmentioning
confidence: 99%
“…Many attack graph based alert correlation techniques have been proposed recently. The correlation methods proposed in the last decade can be classified into three categories [43], [45]: implicit, semiexplicit, and explicit correlations.…”
Section: A Attack Modelingmentioning
confidence: 99%
“…The obligations are expressed as OrBAC concrete rules. The reaction decision is taken by considering the topology information of the monitored system, the reaction obligations and the impact of the elected reactions [13]. A diagnosis is also sent by the RDP to the PIE and handled at the high reaction level.…”
Section: Reaction Decision Point (Rdp)mentioning
confidence: 99%
“…Notice that a diagnosis is derived within this step for improving the reaction process. Activating an automatic or a manual response depends on the confidence level of the diagnosis and the automatic choice may be performed by measuring the impact of the corresponding reaction [13].…”
Section: Mid Level Reactionmentioning
confidence: 99%