• DocumentCode
    391241
  • Title

    Optimization and control problems in Real-time Intrusion Detection

  • Author

    Cabrera, João B D ; Lee, Wei-Jen ; Prasanth, Ravi K. ; Lewis, Lundy ; Mehra, Raman K.

  • Author_Institution
    Sci. Syst. Co., Woburn, MA, USA
  • Volume
    2
  • fYear
    2002
  • fDate
    10-13 Dec. 2002
  • Firstpage
    1408
  • Abstract
    Real-time Intrusion Detection Systems attempt to detect and respond to attacks in real time, i.e. while they are unfolding. When the available computation time is scarce, we have a trade-off involving the computation time of the detection rules and: (1) the accuracy of the rules given by their detection and false alarm rates, (2) the likelihood that a given attack is present, which depends on the prior probability of the attacks, and (3) the damage costs and false alarm costs of the attacks. This paper describes a collection of 0/1 Integer Programming Problems that are associated with the selection of appropriate Rule Portfolios for Real Time Intrusion Detection Systems. The problems are shown to have Knapsack and Set Packing constraints. Due to the inherent uncertainty of the parameters in the cost models, a robust version of the problem is also studied, where parametric uncertainties are allowed to be present. The Linear Programming Relaxation of the robust problem is shown to be convex, opening the possibility of concrete utilization of the proposed methodology. Preliminary results on a research testbed are presented.
  • Keywords
    linear programming; optimisation; robust control; safety systems; integer programming; intrusion detection systems; parametric uncertainties; real time intrusion detection; robust problem; rule portfolios; Concrete; Costs; Educational institutions; Intrusion detection; Linear programming; Monitoring; Portfolios; Real time systems; Robustness; Uncertainty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Decision and Control, 2002, Proceedings of the 41st IEEE Conference on
  • ISSN
    0191-2216
  • Print_ISBN
    0-7803-7516-5
  • Type

    conf

  • DOI
    10.1109/CDC.2002.1184715
  • Filename
    1184715