<  Retour au portail Polytechnique Montréal

A retroactive-burst framework for automated intrusion response system

Alireza Shameli-Sendi, Julien Desfossez, Michel Dagenais et Masoume Jabbarifar

Article de revue (2013)

Document en libre accès dans PolyPublie et chez l'éditeur officiel
[img]
Affichage préliminaire
Libre accès au plein texte de ce document
Version officielle de l'éditeur
Conditions d'utilisation: Creative Commons: Attribution (CC BY)
Télécharger (443kB)
Afficher le résumé
Cacher le résumé

Abstract

The aim of this paper is to present an adaptive and cost-sensitive model to prevent security intrusions. In most automated intrusion response systems, response selection is performed locally based on current threat without using the knowledge of attacks history. Another challenge is that a group of responses are applied without any feedback mechanism to measure the response effect. We address these problems through retroactive-burst execution of responses and a Response Coordinator (RC) mechanism, the main contributions of this work. The retroactive-burst execution consists of several burst executions of responses with, at the end of each burst, a mechanism for measuring the effectiveness of the applied responses by the risk assessment component. The appropriate combination of responses must be considered for each burst execution to mitigate the progress of the attack without necessarily running the next round of responses, because of the impact on legitimate users. In the proposed model, there is a multilevel response mechanism. To indicate which level is appropriate to apply based on the retroactive-burst execution, we get help from a Response Coordinator mechanism. The applied responses can improve the health of Applications, Kernel, Local Services, Network Services, and Physical Status. Based on these indexes, the RC gives a general overview of an attacker's goal in a distributed environment.

Sujet(s): 2700 Technologie de l'information > 2700 Technologie de l'information
2700 Technologie de l'information > 2721 Systèmes et réseaux multimédias
Département: Département de génie informatique et génie logiciel
Organismes subventionnaires: CRSNG/NSERC, Ericsson Software Research, Defense Research and Development Canada (FRDC)
URL de PolyPublie: https://publications.polymtl.ca/3639/
Titre de la revue: Journal of Computer Networks and Communications (vol. 2013)
Maison d'édition: Hindawi
DOI: 10.1155/2013/134760
URL officielle: https://doi.org/10.1155/2013/134760
Date du dépôt: 30 avr. 2019 12:12
Dernière modification: 10 avr. 2024 06:14
Citer en APA 7: Shameli-Sendi, A., Desfossez, J., Dagenais, M., & Jabbarifar, M. (2013). A retroactive-burst framework for automated intrusion response system. Journal of Computer Networks and Communications, 2013, 1-8. https://doi.org/10.1155/2013/134760

Statistiques

Total des téléchargements à partir de PolyPublie

Téléchargements par année

Provenance des téléchargements

Dimensions

Actions réservées au personnel

Afficher document Afficher document