• DocumentCode
    1977746
  • Title

    An analytical framework for reasoning about intrusions

  • Author

    Upadhyaya, Shambhu ; Chinchani, Ramkumar ; Kwiat, Kevin

  • Author_Institution
    Dept. of Comput. Sci. & Eng., State Univ. of New York, Buffalo, NY, USA
  • fYear
    2001
  • fDate
    2001
  • Firstpage
    99
  • Lastpage
    108
  • Abstract
    Local and wide area network information assurance analysts need current and precise knowledge about their system activities in order to address the challenges of critical infrastructure protection. In particular, the analyst needs to know in real-time that an intrusion has occurred so that an active response and recovery thread can be created rapidly. Existing intrusion detection solutions are basically after-the-fact, thereby offering very little in terms of damage confinement and restoration of service. Quick recovery is only possible if the assessment scheme has low latency and it occurs in real-time. The objective of the paper is to develop a reasoning framework to aid in the real-time detection and assessment task that is based on a novel idea of encapsulation of owner´s intent. The theoretical framework developed here will help resolve dubious circumstances that may arise while inferring the premises of operations (encapsulated from owner´s intent) by way of examining the observed conclusions resulting from the actual operations of the owner. This reasoning is significant in view of the fact that intrusion signaling is not a binary decision unlike error detection in traditional fault tolerance. Our reasoning framework has been developed by leveraging the concepts of cost analysis and pricing under uncertainty found in economics and finance. Our main result is the modeling of user activity on a computing system as a martingale and the subsequent quantification of the cost of performing a job to enable decision making
  • Keywords
    computer network management; fault tolerant computing; real-time systems; safety systems; system recovery; active response; analytical framework; cost analysis; critical infrastructure protection; decision making; error detection; intrusion detection solutions; intrusion signaling; martingale; network information assurance analysts; real-time assessment scheme; reasoning framework; recovery thread; system activities; user activity modeling; Costs; Delay; Encapsulation; Fault detection; Information analysis; Intrusion detection; Protection; Signal resolution; Wide area networks; Yarn;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Reliable Distributed Systems, 2001. Proceedings. 20th IEEE Symposium on
  • Conference_Location
    New Orleans, LA
  • ISSN
    1060-9857
  • Print_ISBN
    0-7695-1366-2
  • Type

    conf

  • DOI
    10.1109/RELDIS.2001.969760
  • Filename
    969760