An optimal metric-aware response selection strategy for intrusion response systems

Nadine Herold, Matthias Wachs, Stephan A. Posselt, Georg Carle

Publikation: Beitrag in Buch/Bericht/KonferenzbandKonferenzbeitragBegutachtung

2 Zitate (Scopus)

Abstract

Due to the ever increasing number and variety of security incidents, incident management is an important and challenging aspect of operating indispensable services. Self-protection capabilities ensure service continuity by detecting and counteracting security incidents. Within this process, determining the set of countermeasures to be applied is essential. But detecting and analyzing security incidents in a complex network environment—especially under the pressure of an ongoing incident—is a challenge usually too complex for human comprehension and capabilities. As a consequence, often catastrophic and exaggerated actions are chosen when manually antagonizing security incidents. In this paper, we propose a novel approach towards automatic response selection to counteract security incidents in complex network environments and, by relieving network operators, increase network security. Our approach is based on defining response selection as a mathematical optimization problem and providing a proven optimal combination of countermeasures. Our approach pays respect to user-defined cost metrics for countermeasures and supports restrictions like conflicting countermeasures and resource restrictions in the network. To ensure the usability and scalability of our approach, we evaluate the performance and show the applicability in different network settings.

OriginalspracheEnglisch
TitelFoundations and Practice of Security - 9th International Symposium, FPS 2016, Revised Selected Papers
Redakteure/-innenJoaquin Garcia-Alfaro, Frederic Cuppens, Nora Cuppens-Boulahia, Lingyu Wang, Nadia Tawbi
Herausgeber (Verlag)Springer Verlag
Seiten68-84
Seitenumfang17
ISBN (Print)9783319519654
DOIs
PublikationsstatusVeröffentlicht - 2017
Veranstaltung9th International Symposium on Foundations and Practice of Security, FPS 2016 - Quebec, Kanada
Dauer: 24 Okt. 201626 Okt. 2016

Publikationsreihe

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Band10128 LNCS
ISSN (Print)0302-9743
ISSN (elektronisch)1611-3349

Konferenz

Konferenz9th International Symposium on Foundations and Practice of Security, FPS 2016
Land/GebietKanada
OrtQuebec
Zeitraum24/10/1626/10/16

Fingerprint

Untersuchen Sie die Forschungsthemen von „An optimal metric-aware response selection strategy for intrusion response systems“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren