GUIDEX: A game-theoretic incentive-based mechanism for intrusion detection networks

Q Zhu, C Fung, R Boutaba… - IEEE Journal on Selected …, 2012 - ieeexplore.ieee.org
IEEE Journal on Selected Areas in Communications, 2012ieeexplore.ieee.org
Traditional intrusion detection systems (IDSs) work in isolation and can be easily
compromised by unknown threats. An intrusion detection network (IDN) is a collaborative
IDS network intended to overcome this weakness by allowing IDS peers to share detection
knowledge and experience, and hence improve the overall accuracy of intrusion
assessment. In this work, we design an IDN system, called GUIDEX, using game-theoretic
modeling and trust management for peers to collaborate truthfully and actively. We first …
Traditional intrusion detection systems (IDSs) work in isolation and can be easily compromised by unknown threats. An intrusion detection network (IDN) is a collaborative IDS network intended to overcome this weakness by allowing IDS peers to share detection knowledge and experience, and hence improve the overall accuracy of intrusion assessment. In this work, we design an IDN system, called GUIDEX, using game-theoretic modeling and trust management for peers to collaborate truthfully and actively. We first describe the system architecture and its individual components, and then establish a game-theoretic framework for the resource management component of GUIDEX. We establish the existence and uniqueness of a Nash equilibrium under which peers can communicate in a reciprocal incentive compatible manner. Based on the duality of the problem, we develop an iterative algorithm that converges geometrically to the equilibrium. Our numerical experiments and discrete event simulation demonstrate the convergence to the Nash equilibrium and the security features of GUIDEX against free riders, dishonest insiders and DoS attacks.
ieeexplore.ieee.org