DocumentCode
1350283
Title
Forecasting for Return on Security Information Investment: New Approach on Trends in Intrusion Detection and Unwanted Internet Traffic
Author
Pontes, E. ; Guelfi, A. ; Alonso, E.
Author_Institution
Inst. de Pesquisas Tecnol. de Sao Paulo (IPT), Sao Paulo, Brazil
Volume
7
Issue
4
fYear
2009
Firstpage
438
Lastpage
445
Abstract
The methods used to determine the return on security investment (ROSI) concern historic incidents´ analysis, cost avoidance resulting from resistance, recognition and reconstitution efforts. Although some ROSI methods consider security incidents´ likelihood, they don´t approach studies about forecasts and trends of incidents or unwanted events. Likewise other sciences (seismology, meteorology, vulcanology, and economics) in which extent efforts are done for forecasts, information technology and information security may analyze tendencies, as Internet traffic and intrusion detection trends. The aim of this paper is to show a forecasting approach which could be aggregated to common ROSI methods. In this study, forecasting approach is based on two trend techniques: moving averages and Fibonacci sequence - for security incidents with intrusion detection system (IDS) and unwanted Internet traffic. Tests applied over two datasets (DARPA, KDD), with an IDS, showed that the employed techniques define incidents trends; therefore, forecasting approach may be complementary to ROSI methods.
Keywords
Fibonacci sequences; Internet; security of data; telecommunication security; telecommunication traffic; DARPA; Fibonacci sequence; KDD; ROSI method; cost avoidance; forecasting approach; information security; information technology; intrusion detection system; moving average; return-on-security information investment; security incident likelihood; unwanted Internet traffic; Costs; Economic forecasting; Information security; Internet; Intrusion detection; Investments; Meteorology; Seismology; Technology forecasting; Weather forecasting; Fibonacci sequence; Return on security investment (ROSI); forecasting; intrusion detection; moving average; unwanted Internet traffic;
fLanguage
English
Journal_Title
Latin America Transactions, IEEE (Revista IEEE America Latina)
Publisher
ieee
ISSN
1548-0992
Type
jour
DOI
10.1109/TLA.2009.5349043
Filename
5349043
Link To Document