An intrusion response decision-making model based on hierarchical task network planning

被引:42
|
作者
Mu, Chengpo [1 ]
Li, Yingjiu [2 ]
机构
[1] Beijing Inst Technol, Key Lab Mech Engn & Control, Beijing 100081, Peoples R China
[2] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
关键词
Automated intrusion response system; Hierarchical task network planning; Intrusion response decision-making; Intrusion detection;
D O I
10.1016/j.eswa.2009.07.079
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An intrusion response decision-making model based on hierarchical task network (HTN) planning is presented in the paper. Compared with other response decision-making models, the response decision-making model consists of not only the response measure decision-making process but also response time decision-making process that is firstly proposed in the paper. The response time decision-making model is able to determine response time for different response HTN subtasks. Owing to the introduction of the response time decision-making, the intrusion response system can apply different response strategies to achieve different response goals set by administrators. The proposed response measure decision-making model can optimize a response plan by balancing the response effectiveness and the response negative impact in both a single response measure and a set of response measures. The response decision-making model is self-adaptive and has the ability of tolerating to false positive IDS alerts. The proposed model has been used in the intrusion detection alert management and intrusion response system (IDAM&IRS) developed by us. The functions and architecture of IDAM&IRS are introduced in this paper. In addition, the intrusion response experiments of IDAM&IRS are presented, and the features of the response decision-making model are summarized. (C) 2009 Elsevier Ltd. All rights reserved.
引用
收藏
页码:2465 / 2472
页数:8
相关论文
共 50 条
  • [31] Decision-Making System and Operational Risk Framework for Hierarchical Production Planning
    Vargas, Alix
    Day, Saumen
    Boza, Andres
    Ortiz, Angel
    Ludascher, Bertram
    Sacala, Ioan Stefan
    Moisescu, Mihnea Alexandru
    CONTROL ENGINEERING AND APPLIED INFORMATICS, 2016, 18 (03): : 72 - 81
  • [32] A standardized decision-making task
    Le Bras, Alexandra
    LAB ANIMAL, 2021, 50 (07) : 166 - 166
  • [33] A standardized decision-making task
    Alexandra Le Bras
    Lab Animal, 2021, 50 : 166 - 166
  • [34] Does the Default Network Represent the 'Model' in Model-Based Decision-Making?
    Kaplan, Raphael
    Deco, Gustavo
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2016, PT I, 2016, 9886 : 535 - 535
  • [35] A Dynamic Decision-Making Approach for Intrusion Response in Industrial Control Systems
    Li, Xuan
    Zhou, Chunjie
    Tian, Yu-Chu
    Qin, Yuanqing
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (05) : 2544 - 2554
  • [36] Sports decision-making model based on data mining and neural network
    Yuan, Chunmei
    Yang, Yikun
    Liu, Yang
    NEURAL COMPUTING & APPLICATIONS, 2021, 33 (09): : 3911 - 3924
  • [37] A decision-making model for mechanism type selection based on neural network
    Bo, Rui-Feng
    Gu, Ying-Kui
    DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2007, 14 : 206 - 213
  • [38] Mandatory lane change decision-making model based on neural network
    Cui J.
    Yu G.
    Zhou B.
    Li C.
    Ma J.
    Xu G.
    Beijing Hangkong Hangtian Daxue Xuebao/Journal of Beijing University of Aeronautics and Astronautics, 2022, 48 (05): : 890 - 897
  • [39] Performance measurement for investment decision-making based on wavelet network model
    Nan, Lin Chao
    Xing, Lru
    Li, Liu
    WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING, VOL 1 AND 2, 2006, : 972 - +
  • [40] Sports decision-making model based on data mining and neural network
    Chunmei Yuan
    Yikun Yang
    Yang Liu
    Neural Computing and Applications, 2021, 33 : 3911 - 3924