On a Difficulty of Intrusion Detection.

Stefan Axelsson · 1999

Research in automated computer security intrusion detection, intrusion detection for short, is maturing. Several difficulties remain to be solved before intrusion detection systems become commonplace as part of real-world security solutions. One such difficulty regards the subject of effectiveness, how successful the intrusion detection system is at actually detecting intrusions with a high degree of certainty. With this as its starting point, this paper discusses the "base-rate fallacy" and how it influences the relative success of an intrusion detection system, under a set of reasonable circumstances. The conclusion is reached that the false-alarm rate quickly becomes a limiting factor. 1 Introduction Many requirements can be placed on an intrusion detection system (IDS for short) such as effectiveness, efficiency, ease of use, security, interoperability, transparency etc., etc. Although much research has gone into the field in the past ten years, the theoretical limits of ...

Read the paper · More papers on PaperTik