Intrusion-Detection Policies for IT Security Breaches
Published Online:1 Feb 2008https://doi.org/10.1287/ijoc.1070.0222
References
- Intrusion detection fly-off: Implications for the United States Navy. (1997) . MITRE Technical Report MTR 97W096, MITRE, McLean, VAGoogle Scholar
- The base-rate fallacy and the difficulty of intrusion detection. ACM Trans. Inform. System Security (2000) 3:186–205Crossref, Google Scholar
- Configuration of detection software: A comparison of decision and game theory approaches. Decision Anal. (2004) 1:131–148Link, Google Scholar
- The effect of internet security breach announcements on market value: Capital market reaction for breached firms and internet security developers. Internat. J. Electronic Commerce (2004) 9:69–105Crossref, Google Scholar
- The value of intrusion detection systems (IDSs) in information technology (IT) security. Inform. Systems Res. (2005) 16:28–46Link, Google Scholar
- An intrusion detection model. IEEE Trans. Software Engrg. (1987) 13:222–232Crossref, Google Scholar
- An immunological approach to change detection: Algorithms, analysis, and implications. IEEE Sympos. Security and Privacy (1996) (IEEE Press, New York) Crossref, Google Scholar
- Minimax policies for unobservable inspections. Math. Oper. Res. (1982) 7:139–153Link, Google Scholar
- Testing and evaluating computer intrusion detection systems. Comm. ACM (1999) 42:53–61Crossref, Google Scholar
- Intrusion Detection: Network Security Beyond the Firewall (1998) (John Wiley & Sons, New York) Google Scholar
- Gartner Hype cycle for information security. (2003) . Gartner Research Report, Gartner, Stamford, CTGoogle Scholar
- Using information security as a response to competitor analysis systems. Comm. ACM (2001) 44:70–75Crossref, Google Scholar
- Honeynet ProjectKnow Your Enemy: Learning about Security Threats (2004) (Addison-Wesley, Boston) Google Scholar
- The effect of intrusion detection management methods on the return on investment. Comput. Security (2004) 23:213–228Crossref, Google Scholar
- A quantitative model of the security intrusion process based on attacker behavior. IEEE Trans. Software Engrg. (1997) 23:235–245Crossref, Google Scholar
- A pattern matching model for misuse intrusion detection. The COAST Project (1996) (Purdue University, West Lafayette, IN) Google Scholar
- Toward cost-sensitive modeling for intrusion detection and response. J. Comput. Security (2001) 10:5–22Crossref, Google Scholar
- Evaluating intrusion detection systems: The 1998 DARPA off-line intrusion detection evaluation. Proc. 2000 DARPA Inform. Survivability Conf. Exposition (2000) (IEEE Press, Los Alamitos, CA) 12–26Google Scholar
- A survey of intrusion detection systems. Comput. Security (1993) 12:405–418Crossref, Google Scholar
- A simulation model for managing survivability of networked information systems. (2000) . Technical Report, Carnegie Mellon Software Engineering Institute, Carnegie Mellon University, PittsburghGoogle Scholar
- Experience with emerald to date. Proc. First USENIX Workshop on Intrusion Detection and Network Monitoring (1999) Santa Clara, CA:73–80Google Scholar
- NSS GroupIntrusion Detection Systems Group Test (2001) 2nd ed.(Oakwood House, Wennington, Cambridgeshire, UK) Google Scholar
- Optimal scheduling of inspections: A delayed Markov model with false positives and negatives. Oper. Res. (1991) 39:261–273Link, Google Scholar
- Penetration state transition analysis: A rule based intrusion detection approach. IEEE Eighth Annual Comput. Security Appl. Conf. (1992) (IEEE Press, Los Alamitos, CA) 220–229Crossref, Google Scholar
- Emerald: Event monitoring enabling responses to anomalous live disturbances. Proc. 20th National Inform. Systems Security Conf. (1997) (National Institute of Standards and Technology, Baltimore) 353–365Google Scholar
- A software platform for testing intrusion detection systems. IEEE Software (1997) 14:43–51Crossref, Google Scholar
- Introduction to Stochastic Dynamic Programming (1983) (Academic Press, New York) Google Scholar
- Computer Security Basics (1992) (O'Reilly & Associates, Inc., Sebastopol, CA) Google Scholar
- ISS realsecure pushes past newer IDS players. Network Comput. (1999) 10:95–111Google Scholar
- Honeypots: Tracking Hackers (2002) (Addison-Wesley, Boston) Google Scholar
- A decision analysis method for evaluating computer intrusion detection systems. Decision Anal. (2004) 1:35–50Link, Google Scholar
- New directions for the AAPHID architecture. Recent Advances in Intrusion Detection (1999) (Purdue University, West Lafayette, IN) Google Scholar

