Article ID: | iaor20084220 |
Country: | Netherlands |
Volume: | 177 |
Issue: | 3 |
Start Page Number: | 1824 |
End Page Number: | 1838 |
Publication Date: | Mar 2007 |
Journal: | European Journal of Operational Research |
Authors: | Benabdallah S., Fessi B.A., Hamdi M., Boudriga N. |
Keywords: | decision theory: multiple criteria |
This paper presents a multi-attribute decisional framework for computer network intrusion detection. First, a cost model that allows to estimate accurately the damage resulting from a security incident is described. Then, a multi-attribute optimization algorithm is applied to select the optimal decision based on alternatives to remedy such incidents. The major interest is that the proposed approach can be applied in collaborative reactive intrusion detection where human experts are assisted by automated tools to find the best response. The approach would allow the possibility to assess the performance of the whole system depending on the performance of each constituents' leading to a definition of optimality conditions on the introduced framework.