An optimal metric-aware response selection strategy for intrusion response systems

Nadine Herold, Matthias Wachs, Stephan A. Posselt, Georg Carle

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Due to the ever increasing number and variety of security incidents, incident management is an important and challenging aspect of operating indispensable services. Self-protection capabilities ensure service continuity by detecting and counteracting security incidents. Within this process, determining the set of countermeasures to be applied is essential. But detecting and analyzing security incidents in a complex network environment—especially under the pressure of an ongoing incident—is a challenge usually too complex for human comprehension and capabilities. As a consequence, often catastrophic and exaggerated actions are chosen when manually antagonizing security incidents. In this paper, we propose a novel approach towards automatic response selection to counteract security incidents in complex network environments and, by relieving network operators, increase network security. Our approach is based on defining response selection as a mathematical optimization problem and providing a proven optimal combination of countermeasures. Our approach pays respect to user-defined cost metrics for countermeasures and supports restrictions like conflicting countermeasures and resource restrictions in the network. To ensure the usability and scalability of our approach, we evaluate the performance and show the applicability in different network settings.

Original languageEnglish
Title of host publicationFoundations and Practice of Security - 9th International Symposium, FPS 2016, Revised Selected Papers
EditorsJoaquin Garcia-Alfaro, Frederic Cuppens, Nora Cuppens-Boulahia, Lingyu Wang, Nadia Tawbi
PublisherSpringer Verlag
Pages68-84
Number of pages17
ISBN (Print)9783319519654
DOIs
StatePublished - 2017
Event9th International Symposium on Foundations and Practice of Security, FPS 2016 - Quebec, Canada
Duration: 24 Oct 201626 Oct 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10128 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Symposium on Foundations and Practice of Security, FPS 2016
Country/TerritoryCanada
CityQuebec
Period24/10/1626/10/16

Keywords

  • Intrusion response
  • Optimization
  • Self-protection

Fingerprint

Dive into the research topics of 'An optimal metric-aware response selection strategy for intrusion response systems'. Together they form a unique fingerprint.

Cite this