Simulation-Based Study on False Alarms in Intrusion Detection Systems for Organizations Facing Dual Phishing and Dos Attacks

Jeongkeun Shin, Larry Richard Carley, Kathleen M. Carley · 2024

Machine learning-based intrusion detection systems (IDS) have attracted considerable attention for their role in proactively identifying intrusion attempts and facilitating swift organizational response. While numerous researchers have conceptually discussed the potential negative impacts of high false alarms in machine learning-based IDS on organizations and have proposed various methods to reduce them, there is a shortage of studies that explore how these false alarms can exacerbate cyberattack damage in different organizational settings and in the face of various cyberattack campaigns. This paper introduces an agent-based modeling and simulation approach to assess false alarm consequences in machine learning-based IDS during dual Denial of Service (DoS) and phishing attacks. The IDS with distinct false positive rates, constructed using the KDD Cup 1999 dataset with diverse machine learning algorithms, were simulated to analyze how these varying false alarm rates affect the extent of damage caused by phishing and DoS attacks.

Read the paper · More papers on PaperTik