A Hierarchical and Factored POMDP Based Automated Intrusion Response Framework

Xin Zan,Feng Gao,Jiuqiang Han,Xiaoyong Liu
DOI: https://doi.org/10.1109/icste.2010.5608747
2010-01-01
Abstract:In this paper, we formulate intrusion response problem as a factored Partially Observed Markov Decision Process (POMDP) model. Furthermore, a hierarchical planning algorithm is presented to decompose overall POMDP into some small sub-POMDPs and compute global optimal response policy according to MLS heuristic criterion. Meanwhile, reachable attack intention is defined and used to identify false alerts and compress belief state space. Finally, some experiments were performed to compare proposed algorithm with previous approaches and the results show that our approach have a good performance in response accuracy to different attack scenarios and robustness against false alerts.
What problem does this paper attempt to address?