An Architectural Design to Address the Impact of Adaptations on Intrusion Detection Systems

dc.contributor.authorRiley, Ian
dc.contributor.authorMarshall, Allen
dc.contributor.authorQuirk, Logan
dc.contributor.authorGamble, Rose
dc.date.accessioned2022-12-27T19:24:27Z
dc.date.available2022-12-27T19:24:27Z
dc.date.issued2023-01-03
dc.description.abstractMany self-adaptive, autonomous systems rely on component technologies to report anomalies to planning processes that can choose adaptations. What if the analysis technologies themselves need to be adapted? We consider an intrusion detection system (IDS) supported by two component technologies that assist its decision making: a neural network that finds security anomalies and an attack graph that informs the IDS about system states of interest. The IDS’s purpose is to send alerts regarding security anomalies. Planning processes respond to alerts by selecting mitigation strategies. Mitigations are imposed system-wide and can result in adaptations to the analysis technology, such as the IDS. Thus, without adaptation it may reach a state of stagnation in its detection quality. In this paper, we describe an architectural design for an adaptive layer that works directly with an IDS. We examine two use cases involving different mitigation strategies and their impact on the IDS’s supporting components.
dc.format.extent10
dc.identifier.doi10.24251/HICSS.2023.832
dc.identifier.isbn978-0-9981331-6-4
dc.identifier.otherfa0e2035-bcfa-4925-bc7f-7070238f52e5
dc.identifier.urihttps://hdl.handle.net/10125/103466
dc.language.isoeng
dc.relation.ispartofProceedings of the 56th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectSelf-Adaptive Systems and Applications
dc.subjectattack graphs
dc.subjectintrusion detection systems
dc.subjectneural networks
dc.subjectself-adaptive systems
dc.titleAn Architectural Design to Address the Impact of Adaptations on Intrusion Detection Systems
dc.type.dcmitext
prism.startingpage6873

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0669.pdf
Size:
618.17 KB
Format:
Adobe Portable Document Format