Network Security White Papers
Evaluating Host Intrusion Detection Systems.
Overview Host Intrusion Detection Systems (HIDSs) are critical tools needed to provide indepth security to computer systems. Quantitative metrics for HIDSs are necessary for comparing HIDSs or determining the optimal operational point of a HIDS. While HIDSs and Network Intrusion Detection Systems (NIDSs) greatly differ, similar evaluations have been performed on both types of IDSs by assessing metrics associated with the classification algorithm (e.g., true positives, false positives). This dissertation motivates the necessity of additional characteristics to better describe the performance and effectiveness of HIDSs. The proposed additional characteristics are the ability to collect data where an attack manifests (visibility), the ability of the HIDS to resist attacks in the event of an intrusion (attack resiliency), and the ability to timely detect attacks (efficiency).
| Publisher | University of Maryland | File Format | |
|---|---|---|---|
| Date Published | November 2007 | ||
| Format | White Papers | ||
| Topics | |||



