Detecting network intrusions via sampling: a game theoretic approach
Detecting network intrusions via sampling: a game theoretic approach
复制标题
DOI:
10.1109/infcom.2003.1209210
复制
发表时间:
2003-07
期刊:
影响因子:
--
通讯作者:
M. Kodialam;T. V. Lakshman
中科院分区:
文献类型:
--
作者:
M. Kodialam;T. V. Lakshman
In this paper, we consider the problem of detecting an intruding packet in a communication network. Detection is accomplished by sampling a portion of the packets transiting selected network links (or router interfaces). Since sampling entails incurring network costs for real-time packet sampling and packet examination hardware, we would like to develop a network packet sampling strategy to effectively detect network intrusions while not exceeding a given total sampling budget. We consider this problem in a game theoretic framework, where the intruder picks paths (or the network ingress point if only shortest path routing is possible) to minimize chances of detection and where the network operator chooses a sampling strategy to maximize the chances of detection. We formulate the game theoretic problem, and develop sampling schemes that are optimal in this game theoretic setting.