The Value of Intrusion Detection Systems in Information Technology Security Architecture
Published Online:1 Mar 2005https://doi.org/10.1287/isre.1050.0041
References
- Intrusion detection fly-off: Implications for the United States Navy. (1997) . MITRE Technical Report MTR 97W096, McLean, VAGoogle Scholar
- State of the practice of intrusion detection technologies. (2000) . Technical Report CMU/SEI-99-TR-028 ESC-99-028, Pittsburgh, PAGoogle Scholar
- As e-tailing booms on the net, so does the demand for virtual security. Barron’s (1999) 79(4):25Google Scholar
- Intrusion Detection (1999) (Intrusion.Net Books, NJ) Google Scholar
- The base-rate fallacy and the difficulty of intrusion detection. ACM Trans. Inform. System Security (2000) 3(3):186–205Crossref, Google Scholar
- NIST special publication on intrusion detection systems. (2001) . SP-800-31. National Institute of Standards and TechnologyCrossref, Google Scholar
- Agency research in managerial accounting: A survey. J. Accounting Literature (1982) 1:154–213Google Scholar
- Securing network software applications: Introduction. Comm. ACM (2001) 44(2):28–30Crossref, Google Scholar
- Crime and punishment: An economic approach. J. Political Econom. (1968) 76:169–217Crossref, Google Scholar
- CERT (Computer Emergency and Response Team)Detecting Signs of Intrusion (2000) (CERT Security Improvement Modules, Pittsburgh, PA) Google Scholar
- A Workbench for Intrusion Detection Systems (1998) (IBM Zurich Laboratory, Ruschlikon, Switzerland) Google Scholar
- An intrusion detection model. IEEE Trans. Software Engrg. (1987) 13(2):222–232Crossref, Google Scholar
- Reflections on cyberweapons controls. Comput. Security J. (2000) 16(4):43–53Google Scholar
- An immunological approach to change detection: Algorithms, analysis, and implications. Proc. IEEE Sympos. Security Privacy (1996) 110–119Crossref, Google Scholar
- Testing and evaluating computer intrusion detection systems. Comm. ACM (1999) 42(7):53–61Crossref, Google Scholar
- Optimal monitoring policies in agencies. RAND J. Econom. (1986) 17:339–350Crossref, Google Scholar
- Intrusion Detection: Network Security Beyond the Firewall (1998) (John Wiley & Sons, New York) Google Scholar
- A differential games solution to a model of competition between a thief and the police. Management Sci. (1983) 29:686–699Link, Google Scholar
- Strategic considerations in auditing. Accounting Rev. (1985) 60(4):634–650Google Scholar
- Secure Computer and Networks (2000) (CRC Press, Boca Raton, FL) Google Scholar
- Hierarchical management of misuse reports. Proc. Internat. Conf. Comput. Inform. (1996) Ontario, CanadaGoogle Scholar
- The Theory of Learning in Games (1998) (MIT Press, Cambridge, MA) Google Scholar
- Game Theory (1993) (MIT Press, Cambridge, MA) Google Scholar
- . Hype cycle for information security. (2003) May 30(Stamford, CT). Gartner Research ReportGoogle Scholar
- Model-based intrusion detection. Proc. 14th National Comput. Security Conf. (1991) Washington, D.CGoogle Scholar
- The emerging consensus on criminal conduct in cyberspace. UCLA J. Law Tech. (2002) 3Google Scholar
- Games with incomplete information played by Bayesian players, I: Basic model. Management Sci. (1967) 14(3):159–182Link, Google Scholar
- Games with incomplete information played by Bayesian players, II: Bayesian equilibrium points. Management Sci. (1968a) 14(5):320–334Link, Google Scholar
- Games with incomplete information played by Bayesian players, III: The basic probability distribution of the game. Management Sci. (1968b) 14(7):486–502Link, Google Scholar
- Businesses keep spending on security. Inform. Week (2002) January 28Google Scholar
- Ustat: A real-time intrusion detection system for Unix. (1992) . Master’s thesis, Computer Science Department, University of California at Santa Barbara, CAGoogle Scholar
- Internet Security Systems The truth about false positives. (2001) . Technical White Paper, Internet Security Systems, Atlanta, GAGoogle Scholar
- Editor’s preface. J. Comput. Security (1993) 16(4):43–53Google Scholar
- Stochastic and moral hazard. J. Accounting Res. (1985) 23:175–193Crossref, Google Scholar
- Site selection for on-site inspection in arms control. Arms Control (1992) 13(13):439–462Crossref, Google Scholar
- Who are hackers, anyway? U.S. News World Rep. (1999) 17(2):53Google Scholar
- A pattern matching model for misuse intrusion detection. The COAST Project (1996) (Purdue University, West Lafayette, IN) Google Scholar
- Toward cost-sensitive modeling for intrusion detection and response. J. Comput. Security (2002) 10(1/2):5–22Crossref, Google Scholar
- Evaluating intrusion detection systems: The 1998 DARPA off-line intrusion detection evaluation. Proc. 2000 DARPA Inform. Survivability Conf. Exposition (2000a) 2:12–26(DISCEX)Crossref, Google Scholar
- The 1999 DARPA off-line intrusion detection evaluation. Comput. Networks (2000b) 34(2):579–595Crossref, Google Scholar
- Ides: An intelligent system for detecting intruders. Proc. Sympos.: Comput. Security, Threat Countermeasures (1990) Rome, ItalyGoogle Scholar
- A survey of intrusion detection systems. Comput. Security (1993) 12:405–418Crossref, Google Scholar
- A prototype real-time intrusion detection system. Proc. 1988 IEEE Sympos. Security Privacy (1988) Oakland, CACrossref, Google Scholar
- A real-time intrusion detection expert system. (1992) . Technical report, Consumer Science Laboratory, SRI International, Menlo Park, CAGoogle Scholar
- A price leadership method for solving the inspector’s non-constant-sum game. Naval Res. Logist. Quart. (1966) 13:11–33Crossref, Google Scholar
- The inspector’s non-constant-sum game: Its dependence on a system of detectors. Naval Res. Logist. Quart. (1967) 14:275–290Crossref, Google Scholar
- Intranet Security (1998) (Sun Microsystems Press, Santa Clara, CA) Google Scholar
- Testing intrusion detection systems: A critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by Lincoln Laboratory. ACM Trans. Inform. System Security (2000) 3(4):262–294Crossref, Google Scholar
- Defending yourself: The role of intrusion detection systems. IEEE Software (2000) 17(5):42–51Crossref, Google Scholar
- An Overview of Issues in Testing Intrusion Detection Systems (2002) (NIST IR 7007, Gaithersburg, MD) Google Scholar
- Getting the drop on network intruders. Network World (1999) October 4Google Scholar
- Environmental regulations and incentives for compliance audits. J. Accounting Public Policy (1997) 16(2):187–214Crossref, Google Scholar
- Authentication via keystroke dynamics. 4th ACM Conf. Comput. Comm. Security (1997) Zurich, SwitzerlandCrossref, Google Scholar
- Monitoring vis-à-vis investigation in enforcement of law. Amer. Econom. Rev. (1992) 82(3):556–565Google Scholar
- Dragon claws its way to the top. Network Comput. (2001) 20(August):45–67Google Scholar
- National Computer Security CenterA Guide to Understanding Audit in Trusted Systems (1988) Version 2 (June), The Rainbow Series(NCSC-TG-001, Meade, MD) Google Scholar
- Experience with emerald to date. Proc. 1st USENIX Workshop Intrusion Detection Network Monitoring (1999) Santa Clara, CA:73–80Google Scholar
- Allocating audit resources to detect fraud. Rev. Accounting Stud. (1996) 1:161–182Crossref, Google Scholar
- NIST Publication 800-12An Introduction to Computer Security (1996) (National Institute of Standards and Technology, Gaithersburg, MD) Google Scholar
- Evaluating intrusion detection systems without attacking your friends. Network Intrusion Detection (1999) 86Google Scholar
- NSS GroupIntrusion Detection Systems Group Test (2001) Ed. 2(December(Oakwood House, Wennington, Cambridgeshire, UK) Google Scholar
- Corporate Computer and Network Security (2003) (Prentice Hall, NJ) Google Scholar
- Information Security Risk Analysis (2001) (Auerbach Publications, Boca Raton, FL) Crossref, Google Scholar
- The optimal trade-off between the probability and magnitude of fines. Amer. Econom. Rev. (1979) 69:880–891Google Scholar
- Penetration state transition analysis: A rule-based intrusion detection approach. IEEE 8th Annual Comput. Security Appl. Conf. (1992) San Antonio, TX:220–229Crossref, Google Scholar
- Emerald: Event monitoring enabling responses to anomalous live disturbances. Proc. 20th Nat. Inform. Systems Security Conf. (1997) Baltimore, MD:353–365Google Scholar
- CSI/FBI computer crime and security survey. Comput. Security Isssues Trends (2002) 8(1):1–22Google Scholar
- The Practical Intrusion Detection Handbook (2001) (Prentice Hall, NJ) Google Scholar
- Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection (1998) (Secure Networks Inc., Calgary, Alberta, Canada) Google Scholar
- A software platform for testing intrusion detection systems. IEEE Software (1997) 14(5):43–51Crossref, Google Scholar
- Hackers then and now: Answers to some perennial questions. Comput. Security J. (2000) 16(3):11–14Google Scholar
- Computer Security Basics (1992) (O’Reilly & Associates, Inc., Sebastopol, CA) Google Scholar
- Game models for structuring monitoring and enforcement systems. Natural Resource Modeling (1990) 4:143–173Crossref, Google Scholar
- Optimal pilfering policies for dynamic continuous thieves. Management Sci. (1979) 25(6):535–542Link, Google Scholar
- Specific versus general enforcement of the law. J. Political Econom. (1991) 99:1088–1108Crossref, Google Scholar
- Inside the minds of the insider. Security Management (1999) December):34–44Google Scholar
- ISS RealSecure pushes past newer IDS players. Network Comput. (1999) May 17Google Scholar
- Blocking virus requests in Novell bordermanager’s HTTP accelerator. (2002) . Feature article, Novell Appnotes, Waltham, MAGoogle Scholar
- The optimum enforcement of laws. J. Political Econom. (1970) 78:526–536Crossref, Google Scholar
- An infiltration game with time dependent payoff. Naval Res. Logist. Quart. (1976) 23:297–302Crossref, Google Scholar
- Detection, Estimation and Modulation Theory—Part I (2001) (John Wiley, New York) Google Scholar
- Information Security Architecture (2001) (Auerbach Publications, Boca Raton, FL) Google Scholar
- Deterrence and the design of treaty verification systems. IEEE Trans. Systems, Man, Cybernetics (1992) 22:903–915Crossref, Google Scholar
- Intrusion Battleground Evolves. Network World (2001) October 8):53–62Google Scholar
- New directions for the AAPHID architecture. Workshop Recent Adv. Intrusion Detection (1999) (West Lafayette, IN)Google Scholar

