{"title":"Systematization of metrics in intrusion detection systems","authors":"Yufan Huang, Xiaofan He, H. Dai","doi":"10.1145/2746194.2746222","DOIUrl":null,"url":null,"abstract":"Intrusion detection assumes paramount importance in this information era due to its capability of providing security protection to information systems. In addition to advancing the specific intrusion detection techniques, substantial efforts have been devoted to the taxonomy of existing IDSs, mostly focusing on the methodology, audit source and architecture aspects. The employed metric is another decisive factor of IDS performance, yet a systematized understanding in this aspect is still lacking. As an initial effort towards this objective, a categorization of IDS metrics is proposed in this work, where existing IDS metrics are divided into four types - information theoretic, probabilistic, proximity-based, and reliability-based metrics. Simulation studies of several intrusion detection algorithms that match the proposed categorization are also conducted based on the KDD'99 dataset.","PeriodicalId":134331,"journal":{"name":"Proceedings of the 2015 Symposium and Bootcamp on the Science of Security","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-04-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2015 Symposium and Bootcamp on the Science of Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2746194.2746222","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Intrusion detection assumes paramount importance in this information era due to its capability of providing security protection to information systems. In addition to advancing the specific intrusion detection techniques, substantial efforts have been devoted to the taxonomy of existing IDSs, mostly focusing on the methodology, audit source and architecture aspects. The employed metric is another decisive factor of IDS performance, yet a systematized understanding in this aspect is still lacking. As an initial effort towards this objective, a categorization of IDS metrics is proposed in this work, where existing IDS metrics are divided into four types - information theoretic, probabilistic, proximity-based, and reliability-based metrics. Simulation studies of several intrusion detection algorithms that match the proposed categorization are also conducted based on the KDD'99 dataset.