Intrusion Detection Engine Based on Dempster-Shafer's Theory of Evidence

Wei Hu, Jianhua Li, Qiang Gao · 2006

In the decision making process, the uncertainty existing in the network often leads to the failure of intrusion detection or low detection rate. The Dempster-Shafer's theory of evidence in data fusion has solved the problem of how to analyze the uncertainty in a quantitative way. In the evaluation, the ingoing and outgoing traffic ratio and service rate are selected as the detection metrics, and the prior knowledge in the DDoS domain is proposed to assign probability to evidence. Furthermore, the combination rule is used to combine the data collected by two sensors. The curves of belief mass function varied with time are also shown in the paper. Finally, the analysis of experimental results proves the ID detection engine efficient and applicable. The conclusions provide us with the academic foundation for our future implementation

Read the paper · More papers on PaperTik