DocumentCode
391241
Title
Optimization and control problems in Real-time Intrusion Detection
Author
Cabrera, João B D ; Lee, Wei-Jen ; Prasanth, Ravi K. ; Lewis, Lundy ; Mehra, Raman K.
Author_Institution
Sci. Syst. Co., Woburn, MA, USA
Volume
2
fYear
2002
fDate
10-13 Dec. 2002
Firstpage
1408
Abstract
Real-time Intrusion Detection Systems attempt to detect and respond to attacks in real time, i.e. while they are unfolding. When the available computation time is scarce, we have a trade-off involving the computation time of the detection rules and: (1) the accuracy of the rules given by their detection and false alarm rates, (2) the likelihood that a given attack is present, which depends on the prior probability of the attacks, and (3) the damage costs and false alarm costs of the attacks. This paper describes a collection of 0/1 Integer Programming Problems that are associated with the selection of appropriate Rule Portfolios for Real Time Intrusion Detection Systems. The problems are shown to have Knapsack and Set Packing constraints. Due to the inherent uncertainty of the parameters in the cost models, a robust version of the problem is also studied, where parametric uncertainties are allowed to be present. The Linear Programming Relaxation of the robust problem is shown to be convex, opening the possibility of concrete utilization of the proposed methodology. Preliminary results on a research testbed are presented.
Keywords
linear programming; optimisation; robust control; safety systems; integer programming; intrusion detection systems; parametric uncertainties; real time intrusion detection; robust problem; rule portfolios; Concrete; Costs; Educational institutions; Intrusion detection; Linear programming; Monitoring; Portfolios; Real time systems; Robustness; Uncertainty;
fLanguage
English
Publisher
ieee
Conference_Titel
Decision and Control, 2002, Proceedings of the 41st IEEE Conference on
ISSN
0191-2216
Print_ISBN
0-7803-7516-5
Type
conf
DOI
10.1109/CDC.2002.1184715
Filename
1184715
Link To Document