EconPapers    
Economics at your fingertips  
 

Application of adversarial risk testing to anomaly-based network intrusion detection systems

Juan Luis Santos ()
Additional contact information
Juan Luis Santos: University of Alcala - Institute for Economic and Social Analysis (IAES)

Authors registered in the RePEc Author Service: Tomás Mancha-Navarro ()

Journal of Socioeconomic Engineering, 2014, issue 2, 31-40

Abstract: This paper explores the decision-making process in the attacker-defender problem. First the hypothesis testing with Bayesian techniques with a game theoretical approach is presented. The result is improved through adversarial hypothesis testing, which incorporates the responses of attacker and defender in their decision-making processes. In this way it is possible to model in an accurate way how both agents decide their actions taking into account their assumptions on the behavior and mental processes of the other part. Then it presents an application in the field of information security to anomaly-based network intrusion systems. These systems monitor network or system activities for malicious activities or policy violations and produce reports in order to prevent subsequent attacks and help to identify where potential repairs are needed. Currently their algorithms are based on statistical tools with the aim of reducing errors taking into account the trade-off between the alpha and beta errors entailed by these detection systems. We claim the combination of agent-based models and adversarial hypotheses testing has the ability of improving these systems and helps in developing more efficient tools that take into account the rational and adaptive role of attackers.

Keywords: Adversarial risk testing; intrusion detection system; agent-based model (search for similar items in EconPapers)
Date: 2014
References: View references in EconPapers View complete reference list from CitEc
Citations:

Downloads: (external link)
http://www3.uah.es/iaes/soceng/n2_santos.pdf (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:uae:soceng:y:2014:i:2:p:31-40

Access Statistics for this article

More articles in Journal of Socioeconomic Engineering from Instituto Universitario de Análisis Económico y Social Contact information at EDIRC.
Bibliographic data for series maintained by Laura Suarez ().

 
Page updated 2025-03-20
Handle: RePEc:uae:soceng:y:2014:i:2:p:31-40