Optimal Monitoring Policies Considering Loss Costs and Detection Errors for Different Types of Server Attacks  
Author

Mitsuhiro Imaizumi

 

Co-Author(s)

Mitsutaka Kimura

 

Abstract In recent years, cyber attacks against server systems have become increasingly diverse and sophisticated,
and complex attacks that combine multiple attack methods have become more common. Therefore, rather than relying on a single defense measure, it is essential to establish a multilayered and redundant defense framework that integrates countermeasures with different characteristics. This paper formulates three stochastic models for a server system which has the function of FW, IDS andWAF. Attacks due to unauthorized access are detected by IDS, and attacks due to web application vulnerabilities are detected byWAF. In this paper, we formulate the model by considering loss costs and detection errors for different types of cyber attacks. The expected costs until cyber attacks are detected are derived and optimal policies which minimize them are discussed. Finally, numerical examples are given.

 

Keywords Security, WAF, IDS, Defense-in-depth, Expected Cost
   
    Article #:  RQD2026-60
 

Proceedings of 31st ISSAT International Conference on Reliability & Quality in Design
August 5-7, 2026