Configuration of Detection Software: A Comparison of Decision and Game Theory Approaches

Published Online:https://doi.org/10.1287/deca.1040.0022

References

  • Alaric The card fraud detection problem. (2003) . Alaric Systems Ltd., http://www.alaric-systems.co.uk/fractals_problems.htm/Google Scholar
  • Allen J., Christie A., Fithen W., McHugh J., Pickel J., Stoner E. State of the practice of intrusion detection technologies. (2000) . Technical report CMU/SEI-99-TR-028 ESC-99-028, Carnegie Mellon Software Engineering Institute, Pittsburgh, PAGoogle Scholar
  • Chavez T. A decision-analytic stopping rule for validation of commercial software systems. IEEE Trans. Software Engrg. (2000) 26(9):907–918CrossrefGoogle Scholar
  • CNN Knives, guns, fake bombs elude airport security. (2002) . CNN.com (March 26)Google Scholar
  • Computer Crime and Intellectual Property Section (2004) . Criminal Division of the U.S. Department of Justice, http://www.usdoj.gov/criminal/cybercriminalGoogle Scholar
  • Durst R., Champion T., Witten B., Miller E., Spagnuolo L. Testing and evaluating computer intrusion detection systems. Comm. ACM (1999) 42(7):53–61CrossrefGoogle Scholar
  • Fellingham J., Newman P. Strategic considerations in auditing. Accounting Rev. (1985) 60(October):634–650Google Scholar
  • Fudenberg D., Levine D.The Theory of Learning in Games (1998) (MIT Press, Cambridge, MA) Google Scholar
  • Fudenberg D., Tirole J.Game Theory (1993) (MIT Press, Cambridge, MA) Google Scholar
  • Gordon L. A., Loeb M. P. Using information security as a response to competitor analysis systems. Comm. ACM (2001) 44(9):70–75CrossrefGoogle Scholar
  • Harsanyi J. C. Games with incomplete information played by Bayesian players, I: Basic model. Management Sci. (1967) 14(3):159–182LinkGoogle Scholar
  • Harsanyi J. C. Games with incomplete information played by Bayesian players, II: Bayesian equilibrium points. Management Sci. (1968a) 14(5):320–334LinkGoogle Scholar
  • Harsanyi J. C. Games with incomplete information played by Bayesian players, III: The basic probability distribution of the game. Management Sci. (1968b) 14(7):486–502LinkGoogle Scholar
  • Jajodia S., Miller J. Editor's preface. J. Comput. Security (1993) 16(4):43–53Google Scholar
  • Jonsson E., Olovsson T. A quantitative model of security intrusion process based on attacker behavior. IEEE Trans. Software Engrg. (1997) 23(4):235–245CrossrefGoogle Scholar
  • Lee W., Fan W., Miller M., Stolfo S., Zadok E. Toward cost-sensitive modeling for intrusion detection and response. J. Comput. Security (2002) 10(1/2):5–22CrossrefGoogle Scholar
  • Lippmann R., Haines J. W., Fried D. J., Korba J., Das K. The 1999 DARPA off-line intrusion detection evaluation. Comput. Networks (2000) 34(4):579–595CrossrefGoogle Scholar
  • McHugh J. Testing intrusion detection systems: A critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by Lincoln Laboratory. ACM Trans. Inform. System Security (2000) 3(4):262–294CrossrefGoogle Scholar
  • 800-30 Risk management guide for information technology systems. (National Institute of Standards and Technology Special Publication, Gaithersburg, MD) Google Scholar
  • NMAB Configuration management and performance verification of explosives-detection systems. (1998) . Publication NMAB-482-3, National Academy Press, Washington, D.C.Google Scholar
  • Ortalo R., Deswarte Y., Kaaniche M. Experimenting with quantitative evaluation tools for monitoring operational security. IEEE Trans. Software Engrg. (1999) 25(5):633–650CrossrefGoogle Scholar
  • Provost F., Fawcett T. Analysis and visualization of classifier performance: Comparison under imprecise class and cost distributions. Proc. KDD-97 (1997) (AAAI Press, Newport Beach, CA) 43–48Google Scholar
  • Rasmusen E.Games and Information (1998) 2nd ed.(Blackwell, Cambridge, MA) Google Scholar
  • Sarkar S., Sriram R. Bayesian models for early warnings of bank failures. Management Sci. (2001) 47(11):1457–1475LinkGoogle Scholar
  • Shapiro G. P., Masand B. Estimating campaign benefits and modeling lift. Proc. KDD-99 (1999) (ACM Press, San Diego, CA) 185–193CrossrefGoogle Scholar
  • Shapiro G. P., Steingold S. Measuring lift quality in database marketing. SIGKDD Explorations (2000) 2(2):81–86CrossrefGoogle Scholar
  • Sriram T. Blocking virus requests in Novell BorderManager's HTTP accelerator. (2002) . Feature article. Novell Appnotes, http://developer.novell.com/research/appnotes/Google Scholar
  • Steingold S., Wherry R., Shapiro G. P. Measuring real-time predictive models. Proc. IEEE Internat. Conf. Data Mining (2001) San Jose, CA:649–650CrossrefGoogle Scholar
  • Trees H. V.Detection, Estimation and Modulation Theory-Part I (2001) (John Wiley, New York) Google Scholar
  • Ulvila J. W., Gaffney J. E. A decision analysis method for evaluating computer intrusion detection systems. Decision Anal. (2004) 1(1):35–50LinkGoogle Scholar
INFORMS site uses cookies to store information on your computer. Some are essential to make our site work; Others help us improve the user experience. By using this site, you consent to the placement of these cookies. Please read our Privacy Statement to learn more.