Optimization of HIDS Sliding Window Parameters for Enhanced Security: A Risk Tolerance-Based Approach 


Vol. 14,  No. 7, pp. 506-515, Jul.  2025
https://doi.org/10.3745/TKIPS.2025.14.7.506


PDF
  Abstract

As the transition to MSA environments accelerates due to container and Kubernetes technology advancements, network complexity and security threats are increasing. In this context, HIDS emerges as a crucial element for container security and granular monitoring. This study analyzes the impact of HIDS sliding window parameters on alert performance and proposes optimization strategies based on risk tolerance. Experimental results demonstrate that parameter combinations significantly influence alert performance, with variations of 22-31%p in Precision, 24-57%p in Recall, and 10-29%p in F1-score, confirming the importance of parameter configuration. When optimized for different risk tolerance scenarios, high risk tolerance settings showed 13-16%p improvement in Precision compared to medium risk tolerance, while low risk tolerance settings yielded limited improvements of only 1-2%p. This study proves the effectiveness of risk tolerance-based parameter optimization for adjusting HIDS performance according to security contexts in MSA environments. Future research directions include validation across diverse environments, operational efficiency improvements considering system resources and detection time, and the need for dynamic parameter optimization research capable of adaptively responding to evolving attack patterns in real-time.

  Statistics


  Cite this article

[IEEE Style]

P. S. Joon and K. M. Soo, "Optimization of HIDS Sliding Window Parameters for Enhanced Security: A Risk Tolerance-Based Approach," The Transactions of the Korea Information Processing Society, vol. 14, no. 7, pp. 506-515, 2025. DOI: https://doi.org/10.3745/TKIPS.2025.14.7.506.

[ACM Style]

Park Sang Joon and Kim Mi Soo. 2025. Optimization of HIDS Sliding Window Parameters for Enhanced Security: A Risk Tolerance-Based Approach. The Transactions of the Korea Information Processing Society, 14, 7, (2025), 506-515. DOI: https://doi.org/10.3745/TKIPS.2025.14.7.506.