Detecting network intrusions via sampling: a game theoretic approach

Detecting network intrusions via sampling: a game theoretic approach
复制标题

DOI:
10.1109/infcom.2003.1209210
复制
发表时间:
2003-07
期刊:
IEEE INFOCOM 2003. Twenty-second Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE Cat. No.03CH37428)
影响因子:
--
通讯作者:
M. Kodialam;T. V. Lakshman
M. Kodialam;T. V. Lakshman
中科院分区:
其他
文献类型:
--
作者:
M. Kodialam;T. V. Lakshman

文献摘要

被引文献

相似文献

在本文中,我们考虑检测通信网络中入侵数据包的问题。检测是通过对传输选定网络链路(或路由器接口)的数据包的一部分进行采样来完成的。由于采样需要产生实时数据包采样和数据包检查硬件的网络成本,因此我们希望开发一种网络数据包采样策略,以有效检测网络入侵,同时不超过给定的总采样预算。我们在博弈论框架中考虑这个问题,其中入侵者选择路径(如果只能选择最短路径路由,则选择网络入口点)以最小化检测机会,而网络操作员选择采样策略以最大化检测机会。我们制定博弈论问题,并开发在此博弈论设置中最佳的采样方案。
In this paper, we consider the problem of detecting an intruding packet in a communication network. Detection is accomplished by sampling a portion of the packets transiting selected network links (or router interfaces). Since sampling entails incurring network costs for real-time packet sampling and packet examination hardware, we would like to develop a network packet sampling strategy to effectively detect network intrusions while not exceeding a given total sampling budget. We consider this problem in a game theoretic framework, where the intruder picks paths (or the network ingress point if only shortest path routing is possible) to minimize chances of detection and where the network operator chooses a sampling strategy to maximize the chances of detection. We formulate the game theoretic problem, and develop sampling schemes that are optimal in this game theoretic setting.