• DocumentCode
    389569
  • Title

    Evaluating the impact of automated intrusion response mechanisms

  • Author

    Toth, Thomas ; Kruegel, Christopher

  • Author_Institution
    Inst. for Inf. Syst., Tech. Univ. of Vienna, Austria
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    301
  • Lastpage
    310
  • Abstract
    Intrusion detection systems (IDSs) have reached a high level of sophistication and are able to detect intrusions with a variety of methods. Unfortunately, system administrators neither can keep up with the pace that an IDS is delivering alerts, nor can they react upon these within adequate time limits. Automatic response systems have to take over that task. In case of an identified intrusion, these components have to initiate appropriate actions to counter emerging threats. Most current intrusion response systems (IRSs) utilize static mappings to determine adequate response actions in reaction to detected intrusions. The problem with this approach is its inherent inflexibility. Countermeasures (such as changes of firewall rules) often do not only defend against the detected attack but may also have negative effects on legitimate users of the network and its services. To prevent a situation where a response action causes more damage that the actual attack, a mechanism is needed that compares the severity of an attack to the effects of a possible response mechanism. In this paper, we present a network model and an algorithm to evaluate the impact of response actions on the entities of a network. This allows the IRS to select the response among several alternatives which fulfills the security requirements and has a minimal negative effect on legitimate users.
  • Keywords
    security of data; IDS; IRS; automated intrusion response mechanism impact evaluation; countermeasures; emerging threats; firewall rules; intrusion detection systems; intrusion response systems; system administrators; Computer bugs; Computer security; Counting circuits; Information systems; Intrusion detection; Protection; Telecommunication traffic; Timing; Watches; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2002. Proceedings. 18th Annual
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-1828-1
  • Type

    conf

  • DOI
    10.1109/CSAC.2002.1176302
  • Filename
    1176302