Security Evaluation Method Based on Host Resource Availability

Cuixia Gao,Zhitang Li,Haigang Song
DOI: https://doi.org/10.1109/mue.2009.88
2009-01-01
Abstract:After analyzing malicious attacks against host that affect the host resource usage a method is presented to evaluate the security situation of host system based on host resource availability. A group of factors that can reflect the host resource availability features in a fixed time window are selected as the evaluation metrics. Based on the large samples, the information entropy gain method is applied to determine the importance of evaluation results for different metrics. Then by using analytic hierarchy process (AHP) method, the evaluation results are regarded as the normalized abnormality value to evaluate the host risk status. If the value of host risk status is larger than the threshold then an alert is triggered. Experiments show that this method can reasonably evaluate the host risk status caused by most of attacks.
What problem does this paper attempt to address?