Configuration of the Detection Function in a Distributed IDS Using Game Theory

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

With the rise of the Internet-of-Things, networks are becoming abundant and diverse in nature. Classical solutions to defend such networks, such as firewalls or access control, cannot scale appropriately. The use of Intrusion Detection Systems, especially networked-based, is widespread as a means to compensate for these shortcomings. Yet, the resources to monitor each network individually, grows considerably with the number of networks and the number of different attacks. To solve this issue, we present a distributed network IDS composed of several probes that monitor the different networks. Each probe of the IDS has access to a large number of detection libraries for signature-based detection, as well as our own anomaly-based detection library. However using these detection mechanisms has a cost on each probe, the choice of network to monitor and of the libraries to use, is a complex one that depends on the attacker's strategies and the goals of the defender. To optimize the detection function at every step, this paper models the choices as a two-player nonzero-sum game between the attackers of the network and the IDS's configuration. There are several papers in the literature that use game theory to find optimal configurations of distributed IDS. Those works have been extended here and through a thorough analysis of our framework, we have established guidelines for IDSs.

Original languageEnglish
Title of host publication2020 23rd Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2020
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages210-215
Number of pages6
ISBN (Electronic)9781728151274
DOIs
Publication statusPublished - 1 Feb 2020
Event23rd Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2020 - Paris, France
Duration: 24 Feb 202027 Feb 2020

Publication series

Name2020 23rd Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2020

Conference

Conference23rd Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2020
Country/TerritoryFrance
CityParis
Period24/02/2027/02/20

Keywords

  • Agent
  • Communication
  • Context
  • Event
  • Matching
  • Profile

Fingerprint

Dive into the research topics of 'Configuration of the Detection Function in a Distributed IDS Using Game Theory'. Together they form a unique fingerprint.

Cite this