Configuration of Detection Software: A Comparison of Decision and Game Theory Approaches
Published Online:1 Sep 2004https://doi.org/10.1287/deca.1040.0022
References
- Alaric The card fraud detection problem. (2003) . Alaric Systems Ltd., http://www.alaric-systems.co.uk/fractals_problems.htm/Google Scholar
- State of the practice of intrusion detection technologies. (2000) . Technical report CMU/SEI-99-TR-028 ESC-99-028, Carnegie Mellon Software Engineering Institute, Pittsburgh, PAGoogle Scholar
- A decision-analytic stopping rule for validation of commercial software systems. IEEE Trans. Software Engrg. (2000) 26(9):907–918Crossref, Google Scholar
- CNN Knives, guns, fake bombs elude airport security. (2002) . CNN.com (March 26)Google Scholar
- Computer Crime and Intellectual Property Section (2004) . Criminal Division of the U.S. Department of Justice, http://www.usdoj.gov/criminal/cybercriminalGoogle Scholar
- Testing and evaluating computer intrusion detection systems. Comm. ACM (1999) 42(7):53–61Crossref, Google Scholar
- Strategic considerations in auditing. Accounting Rev. (1985) 60(October):634–650Google Scholar
- The Theory of Learning in Games (1998) (MIT Press, Cambridge, MA) Google Scholar
- Game Theory (1993) (MIT Press, Cambridge, MA) Google Scholar
- Using information security as a response to competitor analysis systems. Comm. ACM (2001) 44(9):70–75Crossref, Google Scholar
- Games with incomplete information played by Bayesian players, I: Basic model. Management Sci. (1967) 14(3):159–182Link, Google Scholar
- Games with incomplete information played by Bayesian players, II: Bayesian equilibrium points. Management Sci. (1968a) 14(5):320–334Link, Google Scholar
- Games with incomplete information played by Bayesian players, III: The basic probability distribution of the game. Management Sci. (1968b) 14(7):486–502Link, Google Scholar
- Editor's preface. J. Comput. Security (1993) 16(4):43–53Google Scholar
- A quantitative model of security intrusion process based on attacker behavior. IEEE Trans. Software Engrg. (1997) 23(4):235–245Crossref, Google Scholar
- Toward cost-sensitive modeling for intrusion detection and response. J. Comput. Security (2002) 10(1/2):5–22Crossref, Google Scholar
- The 1999 DARPA off-line intrusion detection evaluation. Comput. Networks (2000) 34(4):579–595Crossref, Google Scholar
- Testing intrusion detection systems: A critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by Lincoln Laboratory. ACM Trans. Inform. System Security (2000) 3(4):262–294Crossref, Google Scholar
- 800-30 Risk management guide for information technology systems. (National Institute of Standards and Technology Special Publication, Gaithersburg, MD) Google Scholar
- NMAB Configuration management and performance verification of explosives-detection systems. (1998) . Publication NMAB-482-3, National Academy Press, Washington, D.C.Google Scholar
- Experimenting with quantitative evaluation tools for monitoring operational security. IEEE Trans. Software Engrg. (1999) 25(5):633–650Crossref, Google Scholar
- Analysis and visualization of classifier performance: Comparison under imprecise class and cost distributions. Proc. KDD-97 (1997) (AAAI Press, Newport Beach, CA) 43–48Google Scholar
- Games and Information (1998) 2nd ed.(Blackwell, Cambridge, MA) Google Scholar
- Bayesian models for early warnings of bank failures. Management Sci. (2001) 47(11):1457–1475Link, Google Scholar
- Estimating campaign benefits and modeling lift. Proc. KDD-99 (1999) (ACM Press, San Diego, CA) 185–193Crossref, Google Scholar
- Measuring lift quality in database marketing. SIGKDD Explorations (2000) 2(2):81–86Crossref, Google Scholar
- Blocking virus requests in Novell BorderManager's HTTP accelerator. (2002) . Feature article. Novell Appnotes, http://developer.novell.com/research/appnotes/Google Scholar
- Measuring real-time predictive models. Proc. IEEE Internat. Conf. Data Mining (2001) San Jose, CA:649–650Crossref, Google Scholar
- Detection, Estimation and Modulation Theory-Part I (2001) (John Wiley, New York) Google Scholar
- A decision analysis method for evaluating computer intrusion detection systems. Decision Anal. (2004) 1(1):35–50Link, Google Scholar

