Stochastic Tools for Network Intrusion Detection
Lu Yu, Richard R. Brooks

TL;DR
This paper models network security as stochastic systems, proposing a hybrid IDS and honeypot scheme optimized via decentralized POMDPs to improve detection and resource management.
Contribution
It introduces a novel stochastic modeling approach for network security, integrating IDS and honeypots with decentralized POMDP-based decision making.
Findings
Effective hybrid security scheme combining IDS and honeypots.
Decentralized POMDP approach optimizes device activity scheduling.
Improved detection and resource allocation in network security.
Abstract
With the rapid development of Internet and the sharp increase of network crime, network security has become very important and received a lot of attention. We model security issues as stochastic systems. This allows us to find weaknesses in existing security systems and propose new solutions. Exploring the vulnerabilities of existing security tools can prevent cyber-attacks from taking advantages of the system weaknesses. We propose a hybrid network security scheme including intrusion detection systems (IDSs) and honeypots scattered throughout the network. This combines the advantages of two security technologies. A honeypot is an activity-based network security system, which could be the logical supplement of the passive detection policies used by IDSs. This integration forces us to balance security performance versus cost by scheduling device activities for the proposed system. By…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
