A possibilistic approach to intrusion detection under imperfect logging protocol

  • Authors:
  • Romdhane Ben Younes;Guy Tremblay

  • Affiliations:
  • UQAM, Montréal, QC, Canada;UQAM, Montréal, QC, Canada

  • Venue:
  • Proceedings of the 6th International Conference on Security of Information and Networks
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

One of the challenges of intrusion detectors is their ability to function properly in an imperfect and uncertain environment. In an imperfect environment, observed events do not always correspond to real events, and real events may stay unobserved. In uncertain environment, the lack of information leads to uncertainty about observed and unobserved events. In this paper, we present a new intrusion detection approach called PIDS (Possibilistic Intrusion Detection System) that can deal both with imperfection---using a model of the logging mechanism called the logging protocol---and uncertainty---using hypothesis about that logging protocol expressed in possibilistic logic. We present a prototype implementation of this new approach along with some preliminary experiments that analyze PIDS behavior when dealing with imperfection.