Eighth IEEE International Symposium on High Assurance Systems Engineering (HASE'04)
Resource-Sensitive Intrusion Detection Models for Network Traffic
Tampa, Florida
March 25-March 26
ISBN: 0-7695-2094-4
Network security has become an important issue in today's extensively interconnected computer world. The industry, academic institutions, small and large businesses and even residences have never been more risk from the increasing onslaught of computer attacks than more recently. Such malicious efforts cause damage ranging from mere violation of confidentiality and issues of privacy up to actual financial losses if business operations are compromised. Intrusion Detection Systems (ids) have been used along with data mining and machine learning efforts to detect intruders. However, with the limitation of organizational resources, it is unreasonable to inspect every network alarm raised by the ids. Towards resource-and cost-sensitive ids models we investigate the Modified Expected Cost of Misclassification as a model selection measure for building goal oriented intrusion detection classifier. The case study presented is that of the DARPA 1998 offline intrusion detection project. The empirical results show promise for building a resource-based intrusion detection model.
Index Terms:
cost-sensitive resource-based intrusion detection, modified expected cost of misclassification, decision trees, network security
Citation:
Taghi M Khoshgoftaar, Mohamed E. Abushadi, "Resource-Sensitive Intrusion Detection Models for Network Traffic," hase, pp.249-258, Eighth IEEE International Symposium on High Assurance Systems Engineering (HASE'04), 2004