Online Risk Assessment of Intrusion Scenarios Using D-S Evidence Theory

  • Authors:
  • C. P. Mu;X. J. Li;H. K. Huang;S. F. Tian

  • Affiliations:
  • School of Mechatronic Engineering, Beijing Institute of Technology, Beijing, P.R. China 100081;School of Computer and Information Technology, Beijing Jiaotong University, Beijing, P.R. China 100044 and School of Information Engineering, NanChang University, NanChang, P.R.China 330029;School of Computer and Information Technology, Beijing Jiaotong University, Beijing, P.R. China 100044;School of Computer and Information Technology, Beijing Jiaotong University, Beijing, P.R. China 100044

  • Venue:
  • ESORICS '08 Proceedings of the 13th European Symposium on Research in Computer Security: Computer Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In the paper, an online risk assessment model based on D-S evidence theory is presented. The model can quantitate the risk caused by an intrusion scenario in real time and provide an objective evaluation of the target security state. The results of the online risk assessment show a clear and concise picture of both the intrusion progress and the target security state. The model makes full use of available information from both IDS alerts and protected targets. As a result, it can deal with uncertainties and subjectiveness very well in its evaluation process. In IDAM&IRS, the model serves as the foundation for intrusion response decision-making.