Journal on Communications ›› 2020, Vol. 41 ›› Issue (7): 121-130.doi: 10.11959/j.issn.1000-436x.2020111

• Papers • Previous Articles     Next Articles

Optimum response scheme of intrusion detection based on information theory

Youliang TIAN1,2,3,Yulong WU1,2,Qiuxian LI1,2   

  1. 1 College of Computer Science and Technology,Guizhou University,Guiyang 550025,China
    2 Guizhou Provincial Key Laboratory of Public Big Data,Guiyang 550025,China
    3 Institute of Cryptography &Data Security,Guizhou University,Guiyang 550025,China
  • Revised:2020-04-14 Online:2020-07-25 Published:2020-08-01
  • Supported by:
    The National Natural Science Foundation of China(U1836205);The National Natural Science Foundation of China(61662009);The National Natural Science Foundation of China(61772008);The Guizhou Provincial Department of Education Science and Technology Top Talent Support Project([2016]060);The Science and Technology Major Support Program of Guizhou Province(20183001);The Guizhou Provincial Science and Technology Plan Project([2017]5788);The Ministry of Education-China Mobile Research Fund Project(MCM20170401);The Joint Science and Technology Foundation of Guizhou Province(LKT201216);The Joint Science and Technology Foundation of Guizhou Province(LH20147476)

Abstract:

Intrusion detection system (IDS) often inevitably presents major security risks caused by FPs and FNs.However,at present,an effective solution has not been found.In order to solve this problem,an optimal response model of intrusion detection based on information theory was proposed.Firstly,the intruder and IDS in the process of intrusion detection were abstracted into random variables,and the attack and defense model of intruder and IDS was constructed according to the results of the confrontation.Secondly,the defense channel of IDS was designed according to the attack and defense model,then the correct detection of IDS was transformed into the problem of successful transmission of 1 bit information in defensive channel.Finally,the defensive capability of the system was measured by analyzing the channel capacity of the defensive channel,the maximum mutual information of the defensive channel was the defensive limit capability of the IDS,and the corresponding strategy distribution was the optimal response strategy of the defensive capability of the system.The experimental results show that the scheme can effectively reduce the loss caused by FPs and FNs.

Key words: intrusion detection system, average mutual information, channel capacity, detection rate, response scheme

CLC Number: 

No Suggested Reading articles found!