Modified evidence theory for performance enhancement of Intrusion Detection Systems

Ciza Thomas, N. Balakrishnan · International Conference on Information Fusion · 2008

Sensor fusion using heterogeneous intrusion detection systems are employed to aggregate different views of the same event in order to improve the detection through detector reinforcement or complementarity. The fusion technique proposed in this paper is expected to combine the intrusion detection system outputs with subjective judgements. In this paper, a new evidence model which is an extension and improvement of the classical Dempster-Shafer theory is proposed. The feasibility of this method is demonstrated via an analysis case study with several simulated detectors using the replayed DARPA data set. The experimental results are validated and a discussion on why and how the new model is useful is provided. The result shows an improvement in the probability of detection along with a reduction in the false alarm rate with the proposed fusion algorithm.

Read the paper · More papers on PaperTik