• DocumentCode
    1350283
  • Title

    Forecasting for Return on Security Information Investment: New Approach on Trends in Intrusion Detection and Unwanted Internet Traffic

  • Author

    Pontes, E. ; Guelfi, A. ; Alonso, E.

  • Author_Institution
    Inst. de Pesquisas Tecnol. de Sao Paulo (IPT), Sao Paulo, Brazil
  • Volume
    7
  • Issue
    4
  • fYear
    2009
  • Firstpage
    438
  • Lastpage
    445
  • Abstract
    The methods used to determine the return on security investment (ROSI) concern historic incidents´ analysis, cost avoidance resulting from resistance, recognition and reconstitution efforts. Although some ROSI methods consider security incidents´ likelihood, they don´t approach studies about forecasts and trends of incidents or unwanted events. Likewise other sciences (seismology, meteorology, vulcanology, and economics) in which extent efforts are done for forecasts, information technology and information security may analyze tendencies, as Internet traffic and intrusion detection trends. The aim of this paper is to show a forecasting approach which could be aggregated to common ROSI methods. In this study, forecasting approach is based on two trend techniques: moving averages and Fibonacci sequence - for security incidents with intrusion detection system (IDS) and unwanted Internet traffic. Tests applied over two datasets (DARPA, KDD), with an IDS, showed that the employed techniques define incidents trends; therefore, forecasting approach may be complementary to ROSI methods.
  • Keywords
    Fibonacci sequences; Internet; security of data; telecommunication security; telecommunication traffic; DARPA; Fibonacci sequence; KDD; ROSI method; cost avoidance; forecasting approach; information security; information technology; intrusion detection system; moving average; return-on-security information investment; security incident likelihood; unwanted Internet traffic; Costs; Economic forecasting; Information security; Internet; Intrusion detection; Investments; Meteorology; Seismology; Technology forecasting; Weather forecasting; Fibonacci sequence; Return on security investment (ROSI); forecasting; intrusion detection; moving average; unwanted Internet traffic;
  • fLanguage
    English
  • Journal_Title
    Latin America Transactions, IEEE (Revista IEEE America Latina)
  • Publisher
    ieee
  • ISSN
    1548-0992
  • Type

    jour

  • DOI
    10.1109/TLA.2009.5349043
  • Filename
    5349043