Ulvila Jacob W, Gaffney John E
Decision Science Associates, Inc., Vienna, VA 22818.
Lockheed Martin, Gaithersburg, MD 20879.
J Res Natl Inst Stand Technol. 2003 Dec 1;108(6):453-73. doi: 10.6028/jres.108.040. Print 2003 Nov-Dec.
This paper presents a comprehensive method for evaluating intrusion detection systems (IDSs). It integrates and extends ROC (receiver operating characteristic) and cost analysis methods to provide an expected cost metric. Results are given for determining the optimal operation of an IDS based on this expected cost metric. Results are given for the operation of a single IDS and for a combination of two IDSs. The method is illustrated for: 1) determining the best operating point for a single and double IDS based on the costs of mistakes and the hostility of the operating environment as represented in the prior probability of intrusion and 2) evaluating single and double IDSs on the basis of expected cost. A method is also described for representing a compound IDS as an equivalent single IDS. Results are presented from the point of view of a system administrator, but they apply equally to designers of IDSs.
本文提出了一种评估入侵检测系统(IDS)的综合方法。它整合并扩展了ROC(接收者操作特征)和成本分析方法,以提供一个预期成本指标。给出了基于该预期成本指标确定IDS最佳运行状态的结果。给出了单个IDS以及两个IDS组合运行的结果。该方法用于:1)根据错误成本和运行环境的敌意程度(以入侵先验概率表示)确定单个和双IDS的最佳运行点;2)基于预期成本评估单个和双IDS。还描述了一种将复合IDS表示为等效单个IDS的方法。结果是从系统管理员的角度呈现的,但它们同样适用于IDS的设计者。