首页|非完全信息下协作式入侵检测系统检测库配置研究

非完全信息下协作式入侵检测系统检测库配置研究

扫码查看
本文研究了有限时间下非完全信息协作式入侵检测系统(IDS)的检测库配置。针对各入侵检测系统面对不同类型攻击时的最优检测库的配置以及检测库分配的矛盾,提出了一种双层检测库配置方法。第1层研究的是各攻击者的策略制定以及对应入侵检测系统的最优检测库配置方案;第2层研究的是如何解决多个入侵检测系统加载同一检测库的矛盾,给出了基于策略共享的集中式分配方法。第1层研究又可分为2步解决:第1步针对攻击者无法获知系统的真实状态、与入侵检测系统之间存在着信息不对称的问题,提出构建一个基于信念的随机博弈框架,通过后向递归算法求解,并证明该解就是博弈的稳态纳什均衡(SNE)策略;第2步通过求解混合Markov决策过程得到各入侵检测系统的最优检测库配置方案。仿真结果表明,本文所提方法能有效地得到协作式入侵检测系统面对不同类型攻击时的最优检测库配置方案。
Research on configuration of detection libraries of cooperative intrusion detection systems under incomplete information
This paper studies the configuration problem of cooperative intrusion detection systems(IDS)with information limitation in finite-time horizon.Aiming at the optimal configuration of the detection libraries when facing different types of attacks and the contradiction in the allocation process,a method of two-layer detection libraries allocation scheme is proposed.In the first layer,the decision-making process of each intrusion detection system and the corre-sponding attacker are studied.In the second layer,the contradiction of loading detection libraries is solved by a centralized resource allocation method based on sharing strategy.In addition,the problem of the first layer can be solved in two steps.Firstly,by virtue of the fact that the attacker is not aware of the state,which leads to the infor-mation asymmetry,a belief-based stochastic game is constructed.And the strategy solved by the backward recur-sion algorithm is a stationary Nash equilibrium(SNE)strategy of the belief-based stochastic game.Secondly,the optimal detection libraries allocation plan can be solved by a hybrid Markov decision process.The simulation results show that the proposed algorithm is effective in obtaining the optimal configuration of detection libraries when facing different types of attacks.

incomplete information gameMarkov decision processintrusion detection system(IDS)re-source allocationnetwork security

石月楼、杨旦杰、冯宇、李永强

展开 >

浙江工业大学信息工程学院 杭州 310023

非完全信息博弈 Markov决策过程 入侵检测系统(IDS) 资源分配 网络安全

国家自然科学基金

61973276

2024

高技术通讯
中国科学技术信息研究所

高技术通讯

CSTPCD北大核心
影响因子:0.19
ISSN:1002-0470
年,卷(期):2024.34(2)
  • 23