Please use this identifier to cite or link to this item: https://hdl.handle.net/2440/36929
Citations
Scopus Web of Science® Altmetric
?
?
Type: Conference paper
Title: Constructing multi-layered boundary to defend against intrusive anomalies: an autonomic detection coordinator
Author: Zhang, Z.
Shen, H.
Citation: 2005 International Conference on Dependable Systems and Networks, 28 June-1 July 2005, Yokohama, Japan : proceedings / sponsored by IEEE Computer Society Technical Committee on Fault-Tolerant Computing, IFIP WG 10.4 on Dependable Computing and Fault Tolerance, IEICE Technical Group on Dependable Computing ; in cooperation with University of Tokyo, Japan ... [et al.], pp. 118-127
Publisher: IEEE Computer Society
Publisher Place: Online
Issue Date: 2005
ISBN: 0769522823
Conference Name: International Conference on Dependable Systems and Networks (2005 : Yokohama-shi, Japan)
Statement of
Responsibility: 
Zonghua Zhang, Hong Shen
Abstract: An autonomic detection coordinator is developed in this paper, which constructs a multi-layered boundary to defend against host-based intrusive anomalies by correlating several observation-specific anomaly detectors. Two key observations facilitate the model formulation: First, different anomaly detectors have different detection coverage and blind spots; Second, diverse operating environments provide different kinds of information to reveal anomalies. After formulating the cooperation between basic detectors as a partially observable Markov decision process, a policy-gradient reinforcement learning algorithm is applied to search in an optimal cooperation manner, with the objective to achieve broader detection coverage and fewer false alerts. Furthermore, the coordinator’s behavior can be adjusted easily by setting a reward signal to meet the diverse demands of changing system situations. A preliminary experiment is implemented, together with some comparative studies, to demonstrate the coordinator’s performance in terms of admitted criteria.
Description: © 2005 IEEE.
DOI: 10.1109/DSN.2005.30
Published version: http://dx.doi.org/10.1109/dsn.2005.30
Appears in Collections:Aurora harvest
Computer Science publications

Files in This Item:
File Description SizeFormat 
hdl36929.pdf349.74 kBPublisher's PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.